Cleartext Password returned in JSON response
Low
P
Pushwoosh
Submitted None
Actions:
Reported by
ryudox
Vulnerability Details
Technical details and impact analysis
Password was returned in the JSON response (For changing of password), which could be recovered by accessing the firefox.exe memory dump. The password string is persistent in the RAM (even after restarting Firefox application) until you restart the computer.
Refer to the .docx for more information
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cleartext Storage of Sensitive Information