- Description
- The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pkr_internet:taskjitsu:0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9546620-3256-4D85-A144-789A12C5F89D"
},
{
"criteria": "cpe:2.3:a:pkr_internet:taskjitsu:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A03C9348-DD01-4CB3-A5E4-153A8AFA7024"
}
],
"operator": "OR"
}
]
}
]