CVE-2020-11821

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
27/04/2020
Last modified:
21/07/2021

Description

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rukovoditel:rukovoditel:2.5.2:*:*:*:*:*:*:*