Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This issue affects Panel: before v2.3.24.
The application stores passwords in plaintext instead of using secure hashing or encryption mechanisms. An attacker who gains access to the database, configuration files, or other storage media where authentication data is stored can read passwords directly without needing to crack them. The recovered passwords can then be used to authenticate in the system as a known user (Use of Known Domain Credentials).
An attacker can gain full access to user accounts in the system, and consequently take control of the management panel, leading to violation of data confidentiality, integrity, and availability.
Elizsoftware Panel should be updated to version v2.3.24 or later. Additionally, it is recommended to immediately change all passwords stored in the system and verify whether passwords have not been previously exposed. Details are available in the vendor references and USOM message (TR-24-1497).
Elizsoftware Panel in versions earlier than v2.3.24.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HElizsoftware Panel
APPElizsoftware< 2.3.24
Related vulnerabilities
SQL Injection umożliwiający wykonanie poleceń w Eliz Software Panel
Stored XSS w Eliz Software Panel — wstrzyknięcie skryptu po stronie serwera
Reflected XSS w Eliz Software Panel przed wersją v2.3.24