VulnerabilityModified
CVE-2020-9337
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
MEDIUM 6.5EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-326
- Affected
- golfbuddyglobal/course manager
- Source
- cve@mitre.org
References
- https://github.com/0xEmma/CVEs/blob/master/CVEs/CVE-2020-9337-Golf-Buddy-Insecure-Passwords.mdThird Party Advisory
- https://help.golfbuddyglobal.com/sList.asp?searchproduct=29&searchcategory=5Vendor Advisory
- https://github.com/0xEmma/CVEs/blob/master/CVEs/CVE-2020-9337-Golf-Buddy-Insecure-Passwords.mdThird Party Advisory
- https://help.golfbuddyglobal.com/sList.asp?searchproduct=29&searchcategory=5Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.