CVE-2022-40295
—CVSS 3.1
4.9 medium
EPSS
<1%p33
Published
()
Modified
Description
The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.
- Vendors
- phppointofsale
- Products
- php point of sale
- Weakness
- CWE-916, CWE-311
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.