OSV 1.4.0 · unreviewed · 修改于 2022-02-02 08:02
发布时间
2022-01-26 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-26 04:15
源文件
advisories/unreviewed/2022/01/GHSA-7f94-wghq-3rp7/GHSA-7f94-wghq-3rp7.json
Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
该公告没有提供结构化的受影响软件包信息。