CVE-2022-2921
Exposure of password hashes in notrinos/notrinos-erp
8.8
HIGH
CVSS 3.1
EPSS 1.1%
Description
The AP officers account is authorized to Backup and Restore the Database, Due to this he/she can download the backup and see the password hash of the System Administrator account, The weak hash (MD5) of the password can be easily cracked and get the admin password.
How to fix CVE-2022-2921
To remediate CVE-2022-2921, upgrade the affected package to a fixed version below.
- —upgrade to 0.7 or later
Is CVE-2022-2921 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |