SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-7385

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive information and gain privileges by accessing the…

MEDIUM 6.8EPSS 1.27%

Does this matter?

Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.

Description

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7033.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.27% probability · 68th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
livezilla/livezilla
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.