Description
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
Remediation
References
Related Vulnerabilities
PostgreSQL Cryptographic Issues Vulnerability (CVE-2012-2143)
Drupal Core 9.3.x Cross-Site Scripting (9.3.0 - 9.3.18)
SharePoint CVE-2021-40482 Vulnerability (CVE-2021-40482)
Microsoft SQL Server CVE-2023-36420 Vulnerability (CVE-2023-36420)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2016-7053)