2022
05.03

Strap versions prior to 3.6.9 and 4.1.5 disclose a user’s password due to simply base64 encoding it and sticking it in a cookie.

No Comment.

Add Your Comment

You must be logged in to post a comment.