Weak Hashing Algorithm Detected in OpenSlides by OpenSlides
CVE-2024-22892

7.5HIGH

Key Information:

Vendor

Openslides

Vendor
CVE Published:
25 September 2024

What is CVE-2024-22892?

OpenSlides version 4.0.15 has been identified to utilize a weak hashing algorithm for storing user passwords, putting sensitive data at risk of unauthorized access. This vulnerability can potentially allow attackers to easily compromise user accounts by exploiting the insufficient cryptographic protection implemented during password storage. It is crucial for users of OpenSlides to take immediate action to upgrade their systems or implement stronger password management practices to safeguard their data.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.