PT-2021-16829 · Unknown · Void Aural Rec Monitor

Published

2021-04-23

·

Updated

2021-05-06

·

CVE-2021-25898

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Void Aural Rec Monitor version 9.0.0.1
Description An issue was discovered in the svc-login.php file. Passwords are stored in unencrypted source-code text files, which is noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server.
Recommendations For Void Aural Rec Monitor version 9.0.0.1, consider encrypting passwords stored in source-code text files to prevent unauthorized access. As a temporary workaround, restrict access to the svc-login.php file to minimize the risk of exploitation.

Exploit

Fix

Cleartext Storage of Sensitive Information

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25898

Affected Products

Void Aural Rec Monitor