Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bookit_consumer | Datalex | * | 2.1 (including) |