CVE Vulnerabilities

CVE-2020-25987

Insertion of Sensitive Information into Log File

Published: Oct 06, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Monocms Monocms 1.0 (including) 1.0 (including)

Potential Mitigations

References