PT-2023-24204 · Highlight · Highlight

Vadman97

·

Published

2023-05-26

·

Updated

2023-06-05

·

CVE-2023-33187

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Highlight versions prior to 6.0.0
Description Highlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript "Show Password" button. This issue arises because the expected behavior of always obfuscating type="password" inputs is not followed when the input type is changed. As a result, customers may unintentionally have their password values recorded when using a "Show Password" button, assuming that switching to type="text" would also prevent recording of the input.
Recommendations For versions prior to 6.0.0, upgrade to version 6.0.0 to ensure that inputs which used to be type="password" continue to be obfuscated even when their type is changed. As a temporary workaround, consider adding the highlight-mask css-class obfuscation to the affected parts of the DOM to prevent unintentional recording of password values.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

AZL-36943
CVE-2023-33187
GHSA-9QPJ-QQ2R-5MCC

Affected Products

Highlight