CVE-2018-16987

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
13/09/2018
Last modified:
03/10/2019

Description

Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squashtest:squash_tm:*:*:*:*:*:*:*:* 1.18.0 (including)