CVE-2018-11639: Dialogic Powermedia Xms

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.

Affected products

  • Dialogic Powermedia Xms: up to and including 3.5; version 3.5 only

Published 2018-07-03. Last modified 2026-06-17.