PT-2023-25446 · Phpjabbers · Phpjabbers Class Scheduling System

CVE-2023-36136

·

Publicado

2023-08-08

·

Atualizado

2023-08-10

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPJabbers Class Scheduling System version 1.0
Description The issue is related to a lack of encryption on passwords when editing a user account, specifically on the update user page. This allows an attacker to capture all user names and passwords in clear text.
Recommendations For PHPJabbers Class Scheduling System version 1.0, consider implementing encryption for passwords when editing user accounts to prevent clear text capture. As a temporary workaround, restrict access to the update user page until a proper encryption mechanism is in place.

Exploit

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36136

Produtos afetados

Phpjabbers Class Scheduling System