Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mx5-42xw-7586

Опубликовано: 10 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

This issue was fixed in version v3.17-2000.

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

This issue was fixed in version v3.17-2000.

EPSS

Процентиль: 10%
0.00199
Низкий

8.2 High

CVSS4

Дефекты

CWE-328

Связанные уязвимости

nvd
24 дня назад

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.

EPSS

Процентиль: 10%
0.00199
Низкий

8.2 High

CVSS4

Дефекты

CWE-328