CVE Vulnerabilities

CVE-2024-6118

Plaintext Storage of a Password

Published: Aug 05, 2024 | Modified: Aug 30, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.

Weakness

Storing a password in plaintext may result in a system compromise.

Affected Software

Name Vendor Start Version End Version
Meetinghub_paperless_meetings Hamastar 2021 (including) 2021 (including)

Potential Mitigations

References