UNKNOWN PyPI

Plone CMS Improper Session Management

GHSA-mq3q-jjph-rp5p · CVE-2008-1394 · PYSEC-2026-734

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.

Ready to move

Start Securing

Free, no credit card | First findings in minutes