CVE Vulnerabilities

CVE-2014-2212

Published: Apr 01, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.

Affected Software

NameVendorStart VersionEnd Version
PoshPosh_project*3.3.0 (including)
PoshPosh_project1.0.1 (including)1.0.1 (including)
PoshPosh_project1.1.0 (including)1.1.0 (including)
PoshPosh_project1.2.0 (including)1.2.0 (including)
PoshPosh_project1.3.0 (including)1.3.0 (including)
PoshPosh_project1.3.2 (including)1.3.2 (including)
PoshPosh_project1.4.2 (including)1.4.2 (including)
PoshPosh_project1.5 (including)1.5 (including)
PoshPosh_project1.5-beta (including)1.5-beta (including)
PoshPosh_project1.5-beta2 (including)1.5-beta2 (including)
PoshPosh_project1.5-rc (including)1.5-rc (including)
PoshPosh_project1.5.1 (including)1.5.1 (including)
PoshPosh_project2.0 (including)2.0 (including)
PoshPosh_project2.0-beta (including)2.0-beta (including)
PoshPosh_project2.0-beta2 (including)2.0-beta2 (including)
PoshPosh_project2.0-p1 (including)2.0-p1 (including)
PoshPosh_project2.0-rc (including)2.0-rc (including)
PoshPosh_project2.1 (including)2.1 (including)
PoshPosh_project2.1-b (including)2.1-b (including)
PoshPosh_project2.1-p1 (including)2.1-p1 (including)
PoshPosh_project2.1-p2 (including)2.1-p2 (including)
PoshPosh_project2.1-rc (including)2.1-rc (including)
PoshPosh_project2.2 (including)2.2 (including)
PoshPosh_project2.2-beta (including)2.2-beta (including)
PoshPosh_project2.2-rc (including)2.2-rc (including)
PoshPosh_project2.2.1 (including)2.2.1 (including)
PoshPosh_project2.2.3 (including)2.2.3 (including)
PoshPosh_project2.3 (including)2.3 (including)
PoshPosh_project3.0 (including)3.0 (including)
PoshPosh_project3.0-beta (including)3.0-beta (including)
PoshPosh_project3.0.1 (including)3.0.1 (including)
PoshPosh_project3.0.2 (including)3.0.2 (including)
PoshPosh_project3.0.3 (including)3.0.3 (including)
PoshPosh_project3.0.4 (including)3.0.4 (including)
PoshPosh_project3.1.0 (including)3.1.0 (including)
PoshPosh_project3.1.1 (including)3.1.1 (including)
PoshPosh_project3.1.2 (including)3.1.2 (including)
PoshPosh_project3.2.1 (including)3.2.1 (including)

References