PT-2023-20970 · Tsplus · Tsplus Remote Work
Published
2023-10-17
·
Updated
2023-10-25
·
CVE-2023-27132
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TSplus Remote Work version 16.0.0.0
Description
The issue concerns the storage of a cleartext password in the HTML source code of the secure single sign-on web portal. Specifically, the password is placed on the
var pass line.Recommendations
For TSplus Remote Work version 16.0.0.0, consider modifying the code to securely store passwords, avoiding cleartext storage in the HTML source code. As a temporary workaround, restrict access to the secure single sign-on web portal to minimize the risk of exploitation.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tsplus Remote Work