#VU49206 Cleartext storage of sensitive information in parse-server - CVE-2020-26288
Published: December 30, 2020
Vulnerability identifier: #VU49206
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-26288
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
parse-server
parse-server
Software vendor:
MeetFox
MeetFox
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores passwords involved in LDAP authentication in cleartext. An attacker with ability to access the application can obtain passwords in clear text.
Remediation
Install updates from vendor's website.