controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
References
Link | Resource |
---|---|
https://github.com/FantasticLBP/Hotels_Server/issues/2 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-08 17:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-7648
Mitre link : CVE-2019-7648
CVE.ORG link : CVE-2019-7648
JSON object : View
Products Affected
hotels_server_project
- hotels_server
CWE
CWE-326
Inadequate Encryption Strength