Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TWIG webmail config.php认证信息获得以及特权提升漏洞
Vulnerability Description
TWIG webmail 2.7.4版本及之前版本的config.php中的默认"basic"安全设置在cookies中储存明文用户名和密码,攻击者可能获得认证信息以及提升特权。
CVSS Information
N/A
Vulnerability Type
N/A