PT-2017-14113 · Net · Writediary

Publicado

2017-10-27

·

Atualizado

2019-10-03

·

CVE-2017-15582

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WriteDiary application version 4.72
Description The issue concerns the use of hardcoded SecretKey and iv variables for AES parameters in the net.MCrypt component of the application. This makes it easier for attackers to obtain the cleartext of stored diary entries.
Recommendations For version 4.72, consider updating the application to use dynamically generated keys and initialization vectors for AES encryption to prevent easy access to stored diary entries. As a temporary workaround, restrict access to the diary entries to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15582

Produtos afetados

Writediary