PT-2017-14113 · Net · Writediary
Publicado
2017-10-27
·
Atualizado
2019-10-03
·
CVE-2017-15582
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WriteDiary application version 4.72
Description
The issue concerns the use of hardcoded
SecretKey and iv variables for AES parameters in the net.MCrypt component of the application. This makes it easier for attackers to obtain the cleartext of stored diary entries.Recommendations
For version 4.72, consider updating the application to use dynamically generated keys and initialization vectors for AES encryption to prevent easy access to stored diary entries. As a temporary workaround, restrict access to the diary entries to minimize the risk of exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Writediary