PT-2022-25331 · Unknown · Application

Edward Prior

·

Published

2022-10-31

·

Updated

2023-10-25

·

CVE-2022-40295

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Application (affected versions not specified)
Description The issue allows authenticated information disclosure, enabling administrators to view unsalted user passwords. This could lead to the compromise of plaintext passwords via offline attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2022-40295

Affected Products

Application