Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T17:20:03Z",
"nvd_published_at": "2008-03-20T00:44:00Z",
"severity": "HIGH"
}