| |
Vulnerability CVE-2020-10554
Published: 2021-02-05
Description: |
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM. |
Type:
CWE-327 (Use of a Broken or Risky Cryptographic Algorithm)
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|