CVE-2001-1537

7.5
HIGHCVSS v3.1 Base Score
1.11%
LOW RiskEPSS (64th percentile)

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

Published: 12/31/2001
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2 Score

5

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

1.11%LOW Exploitation Risk
64th percentile

This vulnerability has a 1.11% probability of being exploited in the next 30 days, ranking higher than 64% of all scored CVEs.

CWE Classification

Advertisement