5
CVSSv2

CVE-2020-24227

Published: 23/11/2020 Updated: 02/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Playground Sessions v2.5.582 (and previous versions) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

playgroundsessions playground sessions

Github Repositories

Playground Sessions - Storing User Credentials in Plaintext

CVE-2020-24227 Playground Sessions - Storing User Credentials in Plaintext Playground Sessions v25582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to C:\Users<USER>\AppData\Roaming\Playground\Local Store#SharedObjects\Playgroundswf\UserProfilessol to extract the email and password Login Page: Password: Dis