CVE Vulnerabilities

CVE-2022-3206

Cleartext Transmission of Sensitive Information

Published: Oct 17, 2022 | Modified: May 14, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named passster using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
PasssterPassster_project*3.5.5.5.2 (excluding)

Potential Mitigations

References