Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q363-f26m-jj5j

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

EPSS

Процентиль: 4%
0.00019
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 4.6
nvd
7 месяцев назад

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

EPSS

Процентиль: 4%
0.00019
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-321