CVE-2014-2212: Posh Project Posh
Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.
The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.
Affected products
- Posh Project Posh: up to and including 3.3.0; version 1.0.1 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.3.2 only; …
Published 2014-04-01. Last modified 2026-06-17.