CVE-2006-3398

high

Description

The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.

References

https://www.pkrinternet.com/taskjitsu/task/3400

http://www.vupen.com/english/advisories/2006/2660

http://www.pkrinternet.com/download/RELEASE-NOTES.txt

Details

Source: Mitre, NVD

Published: 2006-07-06

Updated: 2026-04-16

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00376