ZeroHour

CVE-2022-22789

CVSS 3.1
7.8 high
EPSS
<1%p5
Published
()
Modified
Description

Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.

Vendors
charactell
Products
formstorm
Weakness
CWE-312
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.