VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (383)

page 20 of 20
  • CVE-2022-1044MedMay 12, 2022
    risk 0.00cvss 6.5epss 0.01

    Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.

  • CVE-2021-46440HigMay 3, 2022
    risk 0.00cvss 7.5epss 0.03

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext…

  • CVE-2022-0881MedMar 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.