VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026

CVE-2002-0487

CVE-2002-0487

Description

Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.

Affected products

2
  • cpe:2.3:a:workforceroi:xpede:4.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:workforceroi:xpede:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:workforceroi:xpede:7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.