PT-2017-14113 · Net · Writediary
Published
2017-10-27
·
Updated
2019-10-03
·
CVE-2017-15582
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WriteDiary application version 4.72
Description
The issue concerns the use of hardcoded
SecretKey and iv variables for AES parameters in the net.MCrypt component of the application. This makes it easier for attackers to obtain the cleartext of stored diary entries.Recommendations
For version 4.72, consider updating the application to use dynamically generated keys and initialization vectors for AES encryption to prevent easy access to stored diary entries. As a temporary workaround, restrict access to the diary entries to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Writediary