Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-3131 — Proof-of-concept for CVE-2021-3131: credential disclosure via base64-encoded credentials in URL parameter of 1C:Enterprise 8 web server. | Kitploit
Tools/GitHubGitHub/jet-pentest/cve-2021-3131
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubjet-pentest/cve-2021-3131

CVE-2021-3131

Proof-of-concept for CVE-2021-3131: credential disclosure via base64-encoded credentials in URL parameter of 1C:Enterprise 8 web server.

View Repository
11465 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-3131

[Suggested description]

The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the 'creds' URL parameter.

[VulnerabilityType Other]

CWE-522 Insufficiently Protected Credentials

[Vendor of Product]

1C Company

[Affected Product Code Base]

1C:Enterprise 8 - Tested: 8.3.17.1851

[Affected Component]

Web-server

[Impact Information Disclosure]

true

[Has vendor confirmed or acknowledged the vulnerability?]

true

[Discoverer]

Irina Belyaeva (Jet Infosystems, jet.su)

[Reference]

https://1c-dn.com/1c_enterprise/what_is_1c_enterprise/

Download Tool