Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f94-wghq-3rp7

Опубликовано: 26 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.

Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.

EPSS

Процентиль: 18%
0.00056
Низкий

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.

EPSS

Процентиль: 18%
0.00056
Низкий

Дефекты

CWE-312