PCL Community Edition Login Credential Logging Vulnerability

Vulnerability

A vulnerability in PCL (Plain Craft Launcher) Community Edition versions 2.12.0-beta.5 to 2.12.0-beta.9 allows for accidental logging of third-party login credentials in a local file. While this log file is not automatically shared or uploaded, there is a risk of credential leakage if the user manually sends the log file. This issue has been addressed in version 2.12.0-beta.10.

Impact

According to the advisory, this vulnerability could lead to unauthorized access to user accounts by exposing login credentials.

Remediation

Users are advised to update PCL Community Edition to version 2.12.0-beta.10 or later, where this issue has been fixed.

Added: Jul 23, 2025, 1:16 AM
Updated: Jul 23, 2025, 1:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.1
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.