PT-2022-24560 · Transtek · Transtek Mojodat Fam
Published
2022-09-13
·
Updated
2023-08-08
·
CVE-2022-38769
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Transtek Mojodat FAM (Fixed Asset Management) version 2.4.6
Description
The issue allows remote attackers to fetch cleartext passwords upon a successful login request. This is related to the mobile application in Transtek Mojodat FAM.
Recommendations
For version 2.4.6, consider restricting access to the login functionality until a fix is available. As a temporary workaround, avoid using the mobile application for login requests to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Transtek Mojodat Fam