PT-2017-13640 · Kickbase · Kickbase Bundesliga Manager
Published
2017-11-13
·
Updated
2019-10-03
·
CVE-2017-14711
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kickbase Bundesliga Manager version 2.2.0 and earlier
Description
The issue concerns the transmission of user credentials in cleartext during registration and authentication, specifically the
username and password. This occurs from the client to the server, potentially exposing sensitive information.Recommendations
For versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kickbase Bundesliga Manager