← volver
CVE-2016-6545

iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request

EPSS 3.1%CWE-613
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.
Productos afectados
iTrack · Easy

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →