CVE-2020-14017

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
24/06/2020
Last modified:
29/06/2020

Description

An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing sessions, or view the contents of this file to discover details about a session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:naviwebs:navigate_cms:2.9:r1433:*:*:*:*:*:*


References to Advisories, Solutions, and Tools