CVE-2022-40295 Vulnerability Details

  /     /     /  

CVE-2022-40295 Metadata Quick Info

CVE Published: 31/10/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: TML | Vendor: PHP Point of Sale LLC | Product: PHP Point of Sale
Status : PUBLISHED

CVE-2022-40295 Description

The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-916
CWE Name: CWE-916 Use of Password Hash With Insufficient Computational Effort
Source: PHP Point of Sale LLC

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-410
CAPEC Description: CAPEC-410 Information Elicitation


Source: NVD (National Vulnerability Database).