CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 10.0. It may be remotely exploitable.
CVE
CVE-2008-1393
Severity
HIGH
CVSS
10
EPSS
2.88%
Original NVD Description
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.