7.5
CVE-2019-7648
- EPSS 0.94%
- Veröffentlicht 08.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:27
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hotels Server Project ≫ Hotels Server Version <= 2018-11-05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.94% | 0.563 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://github.com/FantasticLBP/Hotels_Server/issues/2