CVE-2022-3206: Passster < 3.5.5.5.2 - Insecure Storage of Password
Published Oct 17, 2022
·Updated
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.
Affected Software
1 affected component
Passster Project Passster Wordpress<3.5.5.5.2
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-3206?
CVE-2022-3206 is considered a medium severity vulnerability due to the risk of password exposure.
2
How do I fix CVE-2022-3206?
To fix CVE-2022-3206, update the Passster WordPress plugin to version 3.5.5.5.2 or later.
3
What impact does CVE-2022-3206 have on my website?
CVE-2022-3206 can lead to unauthorized access if a sensitive password stored in the cookie is leaked.
4
Which versions of the Passster plugin are affected by CVE-2022-3206?
CVE-2022-3206 affects all Passster WordPress plugin versions prior to 3.5.5.5.2.
5
Is there a known exploit for CVE-2022-3206?
There is no public information indicating an active exploit for CVE-2022-3206 at this time.