Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jxf-pjgf-g7fc

Опубликовано: 26 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

EPSS

Процентиль: 32%
0.00125
Низкий

7.8 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

EPSS

Процентиль: 32%
0.00125
Низкий

7.8 High

CVSS3

Дефекты

CWE-312