vendor:
Dropbox Desktop Client
by:
Yakir Wizman, Viktor Minin, Alexander Korznikov
7,5
CVSS
HIGH
Local Credentials Disclosure
200
CWE
Product Name: Dropbox Desktop Client
Affected Version From: v9.4.49
Affected Version To: v9.4.49
Patch Exists: YES
Related CWE: N/A
CPE: a:dropbox:dropbox_desktop_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Windows Server 2012 R2 64bit
2016
Dropbox Desktop Client v9.4.49 (64bit) Local Credentials Disclosure
Dropbox Desktop Client v9.4.49 is vulnerable to local credentials disclosure, the supplied username and password are stored in a plaintext format in memory process. A potential attacker could reveal the supplied username and password in order to gain access to account.
Mitigation:
Ensure that the Dropbox Desktop Client is updated to the latest version.