VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026

CVE-2002-0487

CVE-2002-0487

Description

Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.

Affected products

3
  • cpe:2.3:a:workforceroi:xpede:4.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:workforceroi:xpede:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:workforceroi:xpede:7.0:*:*:*:*:*:*:*
  • Intellisol/Xpedellm-create
    Range: =4.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.