CVE-2014-3445: Handsomeweb Sos Webpages
Critical severity, CVSS 9.8. EPSS: 5.3% chance of exploitation in the next 30 days.
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
Affected products
- Handsomeweb Sos Webpages: before 1.1.12 (fixed in 1.1.12)
Published 2020-01-28. Last modified 2026-06-17.