The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and previous versions stores cleartext usernames and passwords in cookies, which could allow malicious users to obtain authentication information and gain privileges.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
symfony twig |