CVE-2021-3131
[Suggested description]
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the 'creds' URL parameter.
[VulnerabilityType Other]
CWE-522 Insufficiently Protected Credentials
[Vendor of Product]
1C Company
[Affected Product Code Base]
1C:Enterprise 8 - Tested: 8.3.17.1851
[Affected Component]
Web-server
[Impact Information Disclosure]
true
[Has vendor confirmed or acknowledged the vulnerability?]
true
[Discoverer]
Irina Belyaeva (Jet Infosystems, jet.su)