PT-2025-52456 · Unknown · Turms Server

Xzzz111

·

Published

2025-12-19

·

Updated

2026-01-02

·

CVE-2025-66910

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Turms Server versions prior to 0.10.0-SNAPSHOT
Description The software stores administrator passwords in plaintext within memory, specifically in the rawPassword field of AdminInfo objects, to improve authentication speed. This bypasses the bcrypt protection normally used. An attacker with local system access could obtain these passwords through methods like memory dumps or heap analysis.
Recommendations Update to a version newer than 0.10.0-SNAPSHOT.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-66910

Affected Products

Turms Server