Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 11 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toxicbishop dsa Study Hub
|
|
| CPEs | cpe:2.3:a:toxicbishop:dsa_study_hub:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Toxicbishop dsa Study Hub
|
Mon, 09 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toxicbishop
Toxicbishop dsa-with-tsx |
|
| Vendors & Products |
Toxicbishop
Toxicbishop dsa-with-tsx |
Sat, 07 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba. | |
| Title | dsa-hub-server: Clear-Text Storage of Sensitive Data | |
| Weaknesses | CWE-311 CWE-522 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T18:26:07.074Z
Reserved: 2026-03-02T21:43:19.927Z
Link: CVE-2026-28678
Updated: 2026-03-09T17:39:46.619Z
Status : Analyzed
Published: 2026-03-07T16:15:54.010
Modified: 2026-03-11T17:35:39.667
Link: CVE-2026-28678
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:05:04Z