← back
CVE-2016-6545

iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request

EPSS 3.1%CWE-613
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.
Affected products
iTrack · Easy

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →