Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/5613 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42426 | vdb entry |