Cleartext Password Exposure in Faronics Insight Teacher Console on Windows
CVE-2023-28345
4.6MEDIUM
What is CVE-2023-28345?
Faronics Insight version 10.0.19045 for Windows contains a vulnerability in the Teacher Console application that exposes the console password in cleartext through an API endpoint accessible from localhost. This flaw allows users with physical access to the Teacher Console to exploit the endpoint, using a web browser to retrieve the teacher's password. Once obtained, this password permits unauthorized access to the Teacher Console, potentially enabling attackers to compromise student machines with minimal effort.