CVE-2019-10676
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered within this product, a pop-up window will appear prompting the user if they want to save this new password. This pop-up window will persist on any page the user enters within the browser until a decision is made. The code of the pop-up window can be read by remote servers and contains the login credentials and URL in cleartext. A malicious server could easily grab this information from the pop-up. This is related to id="uniqkey-password-popup" and password-popup/popup.html.
Se ha detectado un problema en Uniqkey Password Manager versión 1.14. Al introducir nuevas credenciales a un sitio que no está registrado dentro de este producto, aparecerá una ventana emergente que le solicitará al usuario si desea guardar esta nueva contraseña. Esta ventana emergente persistirá en cualquier página que el usuario ingresa dentro del navegador hasta que una decisión se haya tomado. El código de la ventana emergente se puede leer por los servidores remotos y contiene las credenciales de inicio de sesión y la dirección URL en texto sin cifrar. Un servidor malicioso podría fácilmente tomar esta información de la ventana emergente. Esto está relacionado con id="uniqkey-password-popup" y password-popup/popup.html.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-31 CVE Reserved
- 2019-04-05 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://cxsecurity.com/issue/WLB-2019040055 | Third Party Advisory | |
https://packetstormsecurity.com/files/152410/Uniqkey-Password-Manager-1.14-Credential-Disclosure.html | Third Party Advisory | |
https://seclists.org/fulldisclosure/2019/Apr/1 | Mailing List | |
https://vuldb.com/?id.132740 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Uniqkey Search vendor "Uniqkey" | Password Manager Search vendor "Uniqkey" for product "Password Manager" | 1.14 Search vendor "Uniqkey" for product "Password Manager" and version "1.14" | - |
Affected
|