UNKNOWN PyPI

Plone Improper Session Management

GHSA-593c-j348-f3gv · CVE-2008-1393 · PYSEC-2026-731

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Plone CMS before 3, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

Ready to move

Start Securing

Free, no credit card | First findings in minutes