{"id":"CVE-2008-1393","aliases":["PYSEC-2026-731"],"url":"https://o3.security/vulnerability/CVE-2008-1393","summary":"Plone Improper Session Management","details":"Plone CMS before 3, places a base64 encoded form of the username and password in the `__ac` cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.","published":"2022-05-01T23:39:38Z","modified":"2026-07-06T08:11:26.765580288Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"plone","fixedVersion":"3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1393"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41427"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"http://plone.org/documentation/how-to/secure-login-without-plain-text-passwords"},{"type":"WEB","url":"http://plone.org/products/plone/roadmap/48?"},{"type":"WEB","url":"http://securityreason.com/securityalert/3754"},{"type":"WEB","url":"http://www.procheckup.com/Hacking_Plone_CMS.pdf"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/489544/100/0/threaded"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-06T08:11:26.765580288Z"}}