CWE-499: Serializable Class Containing Sensitive Data
The code contains a class with sensitive data, but the class does not explicitly deny serialization. The data can be accessed by serializing the class through another class.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-5657 — CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure
Recently published
- CVE-2024-5657 — CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure