PT-2001-2612 · Easynews · Easynews

Published

2001-12-31

·

Updated

2009-04-03

·

CVE-2001-1527

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions easyNews versions 1.5 and earlier
Description The issue allows local users to obtain administration passwords stored in cleartext in the settings.php file, potentially gaining access to the system.
Recommendations For easyNews versions 1.5 and earlier, consider encrypting or hashing administration passwords stored in settings.php to prevent unauthorized access. As a temporary workaround, restrict access to the settings.php file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1527

Affected Products

Easynews