CVE Vulnerabilities

CVE-2020-18406

Insufficiently Protected Credentials

Published: Jun 27, 2023 | Modified: Jul 05, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Cmseasy Cmseasy 7.0 (including) 7.0 (including)

Potential Mitigations

References