The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
History

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
Title Stored credentials in Redmine
First Time appeared Redmine
Redmine redmine
Weaknesses CWE-257
CPEs cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:5.0.14:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:5.1.10:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:6.0.7:*:*:*:*:*:*:*
Vendors & Products Redmine
Redmine redmine
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-06-12T14:00:11.755Z

Reserved: 2026-02-03T15:43:30.850Z

Link: CVE-2026-1836

cve-icon Vulnrichment

Updated: 2026-06-12T14:00:07.862Z

cve-icon NVD

Status : Received

Published: 2026-06-12T14:16:30.817

Modified: 2026-06-12T14:16:30.817

Link: CVE-2026-1836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.