Exposure of password hashes in notrinos/notrinos-erp
High severity
GitHub Reviewed
Published
Aug 22, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 21, 2022
Published to the GitHub Advisory Database
Aug 22, 2022
Reviewed
Aug 30, 2022
Last updated
Jan 28, 2023
The AP officers account is authorized to Backup and Restore the Database, Due to this he/she can download the backup and see the password hash of the System Administrator account, The weak hash (MD5) of the password can be easily cracked and get the admin password.
References