PT-2026-48867 · Redmine · Redmine

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-1836

CVSS v4.0

5.3

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-1836

Affected Products

Redmine