First published: Tue Aug 08 2023(Updated: )
PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Class Scheduling System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36136 is medium.
CVE-2023-36136 affects PHPJabbers Class Scheduling System by lacking encryption on the password when editing a user account, allowing an attacker to capture all user names and passwords in clear text.
Version 1.0 of PHPJabbers Class Scheduling System is affected by CVE-2023-36136.
Yes, you can find references for CVE-2023-36136 at the following links: [https://medium.com/@blakehodder/additional-vulnerabilities-in-php-jabbers-scripts-c6bbd89b24bb](https://medium.com/@blakehodder/additional-vulnerabilities-in-php-jabbers-scripts-c6bbd89b24bb) and [https://www.phpjabbers.com/class-scheduling-system](https://www.phpjabbers.com/class-scheduling-system).
CWE-312 refers to Clear Text Storage of Sensitive Information, which is the vulnerability type associated with CVE-2023-36136.