PT-2023-20970 · Tsplus · Tsplus Remote Work
CVE-2023-27132
·
Publicado
2023-10-17
·
Atualizado
2023-10-25
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TSplus Remote Work version 16.0.0.0
Description
The issue concerns the storage of a cleartext password in the HTML source code of the secure single sign-on web portal. Specifically, the password is placed on the
var pass line.Recommendations
For TSplus Remote Work version 16.0.0.0, consider modifying the code to securely store passwords, avoiding cleartext storage in the HTML source code. As a temporary workaround, restrict access to the secure single sign-on web portal to minimize the risk of exploitation.
Exploit
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tsplus Remote Work