PCL Community Edition Login Credential Logging Vulnerability
Vulnerability
A vulnerability in PCL (Plain Craft Launcher) Community Edition versions 2.12.0-beta.5 to 2.12.0-beta.9 allows for accidental logging of third-party login credentials in a local file. While this log file is not automatically shared or uploaded, there is a risk of credential leakage if the user manually sends the log file. This issue has been addressed in version 2.12.0-beta.10.
Impact
According to the advisory, this vulnerability could lead to unauthorized access to user accounts by exposing login credentials.
Remediation
Users are advised to update PCL Community Edition to version 2.12.0-beta.10 or later, where this issue has been fixed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
