CVE-2020-24227

Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password.
References
Link Resource
https://github.com/nathunandwani/CVE-2020-24227 Exploit Third Party Advisory
https://github.com/nathunandwani/CVE-2020-24227 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:playgroundsessions:playground_sessions:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 05:14

Type Values Removed Values Added
References () https://github.com/nathunandwani/CVE-2020-24227 - Exploit, Third Party Advisory () https://github.com/nathunandwani/CVE-2020-24227 - Exploit, Third Party Advisory

Information

Published : 2020-11-23 21:15

Updated : 2024-11-21 05:14


NVD link : CVE-2020-24227

Mitre link : CVE-2020-24227

CVE.ORG link : CVE-2020-24227


JSON object : View

Products Affected

playgroundsessions

  • playground_sessions
CWE
CWE-522

Insufficiently Protected Credentials