Rukovoditel Cleartext Storage of Sensitive Information Vulnerability - CVE-2020-11821
Reference:
CVE-2020-11821
Title:
Rukovoditel Cleartext Storage of Sensitive Information Vulnerability
Overview:
In Rukovoditel 2.5.2 users39 passwords and usernames are stored in a cookie with URL encoding base64 encoding and hashing. Thus an attacker can easily apply brute force on them.