A Cryptographic Issue vulnerability has been found on...
High severity
Unreviewed
Published
Oct 3, 2023
to the GitHub Advisory Database
•
Updated Sep 23, 2024
Description
Published by the National Vulnerability Database
Oct 3, 2023
Published to the GitHub Advisory Database
Oct 3, 2023
Last updated
Sep 23, 2024
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.
References