Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page.
The product uses a hard-coded, unchangeable cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Helpcom | Cnesty | * | 10.0 (excluding) |