|Date: (C)2008-12-03 (M)2017-08-08|
|CVSS Score: 4.0||Access Vector: NETWORK|
|Exploitability Subscore: 8.0||Access Complexity: LOW|
|Impact Subscore: 2.9||Authentication: SINGLE_INSTANCE|
| ||Confidentiality: PARTIAL|
| ||Integrity: NONE|
| ||Availability: NONE|
member/settings_account.php in Octeth Oempro 188.8.131.52, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.