Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4rq-8hw9-mj8q

Опубликовано: 28 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.2

Описание

Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.  This issue was fixed in 18.2.377 version of the software.

Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.  This issue was fixed in 18.2.377 version of the software.

EPSS

Процентиль: 55%
0.00323
Низкий

8.2 High

CVSS4

Дефекты

CWE-261

Связанные уязвимости

nvd
11 месяцев назад

Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.  This issue was fixed in 18.2.377 version of the software.

EPSS

Процентиль: 55%
0.00323
Низкий

8.2 High

CVSS4

Дефекты

CWE-261