CVE-2020-10554

An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:psyprax:psyprax:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:55

Type Values Removed Values Added
References () https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax - Third Party Advisory () https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax - Third Party Advisory

Information

Published : 2021-02-05 20:15

Updated : 2024-11-21 04:55


NVD link : CVE-2020-10554

Mitre link : CVE-2020-10554

CVE.ORG link : CVE-2020-10554


JSON object : View

Products Affected

psyprax

  • psyprax
CWE
CWE-326

Inadequate Encryption Strength

CWE-522

Insufficiently Protected Credentials