Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 PyPI

Hard coded credentials in FreeTAKServer

GHSA-f897-875p-23x7 · CVE-2022-25510 · PYSEC-2022-43135

Published · Modified

Description

FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.

Ready to move

Start Securing

Free, no credit card | First findings in minutes