# CVE-2001-1537

## Summary

- **CVE ID:** CVE-2001-1537
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** N/A
- **Published:** Jul 14, 2005
- **Last Modified:** Mar 16, 2026

## Description

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html)
- [CNA](http://www.securityfocus.com/bid/3591)
- [CNA](http://www.iss.net/security_center/static/7619.php)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 42.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._