Vulnerabilities (CVE)

Filtered by vendor Ieasytec Subscribe
Filtered by product Itrackeasy
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-6545 1 Ieasytec 1 Itrackeasy 2019-10-09 5.0 MEDIUM 9.8 CRITICAL
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.