exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Uniqkey Password Manager 1.14 Credential Disclosure

Uniqkey Password Manager 1.14 Credential Disclosure
Posted Apr 5, 2019
Authored by Gionathan Reale

Uniqkey Password Manager version 1.14 suffers from a credential disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2019-10676
SHA-256 | 74a9d5a6cd42b3cf5502deaed5ee5abfef3eb39b1b75f9de2df6ab29e1baba27

Uniqkey Password Manager 1.14 Credential Disclosure

Change Mirror Download
Uniqkey Password Manager 1.14 contains a vulnerability which causes remote credential disclosure under certain conditions.

CVE-2019-10676


-------------------------------------------------------------------------------------------------------------------------------------------

When entering new credentials to a site that isn't registered within
the password manager, a pop-up window will appear asking the user
if they want to save these new credentials. This pop-up window will
stay on any page the user visits within the browser until a
decision is made. The code of the pop-up window can be read by remote
servers and contains the login credentials and URL in cleartext.
A malicious server could easily grab this information from the pop-up.
This vulnerability is related to id="uniqkey-password-popup" and password-popup/popup.html.


Fix:

Update to the current version.
-----------------------------------------------------------------------------------------------------------------------------------------------------
Disclosure:

Vendor contacted: 5th Jan 2019
Issue fixed : 23rd Jan 2019
Bug Bounty paid: 4th Feb 2019


The vendor was very professional and responded well most of the time.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close