PT-2021-16829 · Unknown · Void Aural Rec Monitor
Published
2021-04-23
·
Updated
2021-05-06
·
CVE-2021-25898
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Void Aural Rec Monitor version 9.0.0.1
Description
An issue was discovered in the
svc-login.php file. Passwords are stored in unencrypted source-code text files, which is noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server.Recommendations
For Void Aural Rec Monitor version 9.0.0.1, consider encrypting passwords stored in source-code text files to prevent unauthorized access. As a temporary workaround, restrict access to the
svc-login.php file to minimize the risk of exploitation.Exploit
Fix
Cleartext Storage of Sensitive Information
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Void Aural Rec Monitor