The maker of Passwordstate, an enterprise grade password manager for storing companies most privileged credentials, is urging them to promptly install an update fixing a high severity vulnerability that hackers can exploit to gain administrative access to their vaults. The authentication bypass allows hackers to create a URL that accesses an emergency access page for Passwordstate. From there, an attacker could pivot to the administrative section of the password manager. A CVE identifier isnt...

Read the full article at Arstechnica