PT-2015-6577 · Drupal · Hybridauth Social Login

Mike Goulding

+1

·

Publicado

2015-06-15

·

Atualizado

2016-06-09

·

CVE-2015-4395

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions HybridAuth Social Login module versions 7.x-2.x before 7.x-2.10
Description The issue allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database, due to the storage of passwords in plaintext when the "Ask user for a password when registering" option is enabled.
Recommendations For HybridAuth Social Login module versions 7.x-2.x before 7.x-2.10, update to version 7.x-2.10 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4395

Produtos afetados

Hybridauth Social Login