CVE Vulnerabilities

CVE-2022-3206

Cleartext Transmission of Sensitive Information

Published: Oct 17, 2022 | Modified: May 14, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named passster using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Passster Passster_project * 3.5.5.5.2 (excluding)

Potential Mitigations

References