PT-2023-24239 · Starface · Starface
Published
2023-06-01
·
Updated
2024-12-12
·
CVE-2023-33243
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
STARFACE (affected versions not specified)
Description
The web interface and REST API of STARFACE allow authentication using the SHA512 hash of the password instead of the cleartext password. This practice renders the protection of storing password hashes in the database ineffective, as it allows authentication using the hash.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Starface