CWE-317
Cleartext Storage of Sensitive Information in GUI
AI Translation Available
The product stores sensitive information in cleartext within the GUI.
Status
draft
Abstraction
variant
Affected Platforms
Extended Description
AI Translation
An attacker can often obtain data from a GUI, even if hidden, by using an API to directly access GUI objects such as windows and menus. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Technical Details
AI Translation
Common Consequences
confidentiality
Impacts
read memory
read application data