Loading HuntDB...

Cleartext Password returned in JSON response

Low
P
Pushwoosh
Submitted None
Reported by ryudox

Vulnerability Details

Technical details and impact analysis

Cleartext Storage of Sensitive Information
Password was returned in the JSON response (For changing of password), which could be recovered by accessing the firefox.exe memory dump. The password string is persistent in the RAM (even after restarting Firefox application) until you restart the computer. Refer to the .docx for more information

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cleartext Storage of Sensitive Information