Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pr6-2grv-9mc6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.

Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.

EPSS

Процентиль: 21%
0.0007
Низкий

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.

EPSS

Процентиль: 21%
0.0007
Низкий

Дефекты

CWE-326