PT-2023-24239 · Starface · Starface

Published

2023-06-01

·

Updated

2024-12-12

·

CVE-2023-33243

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions STARFACE (affected versions not specified)
Description The web interface and REST API of STARFACE allow authentication using the SHA512 hash of the password instead of the cleartext password. This practice renders the protection of storing password hashes in the database ineffective, as it allows authentication using the hash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-33243

Affected Products

Starface