Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44w5-q257-8428

Опубликовано: 22 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Exposure of password hashes in notrinos/notrinos-erp

The AP officers account is authorized to Backup and Restore the Database, Due to this he/she can download the backup and see the password hash of the System Administrator account, The weak hash (MD5) of the password can be easily cracked and get the admin password.

Пакеты

Наименование

notrinos/notrinos-erp

composer
Затронутые версииВерсия исправления

< 0.7

0.7

EPSS

Процентиль: 63%
0.00437
Низкий

8.8 High

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.

EPSS

Процентиль: 63%
0.00437
Низкий

8.8 High

CVSS3

Дефекты

CWE-359