CVE-2020-15105 affects Django Two-Factor Authentication before version 1.12, where it insecurely stores user passwords in clear text within the session during the login process. The severity is rated as MEDIUM (CVSS 5.4), with a high impact on confidentiality due to the cleartext storage, particularly if database or cache session storage is used. While the attack complexity is high and user interaction is required, successful exploitation could expose user credentials. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12CPE matchmatch criteria | cpe:2.3:a:django_two-factor_authentication_project:django_two-factor_authentication:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.