PT-2022-15677 · Charactell · Charactell - Formstorm Enterprise

Michael Starchenko

·

Published

2022-01-25

·

Updated

2022-02-01

·

CVE-2022-22789

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Charactell - FormStorm Enterprise (affected versions not specified)
Description The issue allows an attacker to modify the passwords file for all users, enabling account takeover. The xx users.ini file in the FormStorm folder stores usernames in cleartext and an obfuscated password. An attacker can replace the existing password in the file to take over an account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22789

Affected Products

Charactell - Formstorm Enterprise