PT-2017-14113 · Net · Writediary

Published

2017-10-27

·

Updated

2019-10-03

·

CVE-2017-15582

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WriteDiary application version 4.72
Description The issue concerns the use of hardcoded SecretKey and iv variables for AES parameters in the net.MCrypt component of the application. This makes it easier for attackers to obtain the cleartext of stored diary entries.
Recommendations For version 4.72, consider updating the application to use dynamically generated keys and initialization vectors for AES encryption to prevent easy access to stored diary entries. As a temporary workaround, restrict access to the diary entries to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15582

Affected Products

Writediary