VYPR
High severity8.8NVD Advisory· Published Apr 5, 2019· Updated Jun 17, 2026

CVE-2019-10884

CVE-2019-10884

Description

Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing campaigns and create a sense of false security.

Affected products

2
  • cpe:2.3:a:uniqkey:password_manager:1.14:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:uniqkey:password_manager:1.14:*:*:*:*:*:*:*
    • (no CPE)range: = 1.14

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.