{"id":"CVE-2008-1394","aliases":["PYSEC-2026-734"],"url":"https://o3.security/vulnerability/CVE-2008-1394","summary":"Plone CMS Improper Session Management","details":"Plone CMS before 3 places a base64 encoded form of the username and password in the `__ac` cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.","published":"2022-05-01T23:39:37Z","modified":"2026-07-06T08:11:25.247218982Z","cvss":null,"epss":{"score":0.01426,"percentile":0.70908,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"plone","fixedVersion":"3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1394"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41425"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"http://plone.org/about/security/overview/security-overview-of-plone"},{"type":"WEB","url":"http://securityreason.com/securityalert/3754"},{"type":"WEB","url":"http://www.procheckup.com/Hacking_Plone_CMS.pdf"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/489544/100/0/threaded"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-06T08:11:25.247218982Z"}}