A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
The ebooknote function saves user authentication credentials directly in XML files without any encryption or password masking (CWE-256, CWE-522). A remote attacker who gains access to such an XML file can read passwords in plaintext. The obtained login credentials can then be used to directly log into the system as another user.
An attacker can obtain authentication credentials of any system users and take over their accounts, gaining full access to the MeetingHub platform with the victim's privileges.
Apply patches available from the vendor according to references. It is also recommended to immediately change passwords for all system users and verify XML files for the presence of plaintext authentication data.
Hamastar MeetingHub Paperless Meetings 2021
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHamastar Meetinghub Paperless Meetings
APPHamastar2021
Related vulnerabilities
Arbitrary File Upload w Hamastar MeetingHub umożliwia RCE bez uwierzytelnienia
Nieograniczony upload plików w Hamastar MeetingHub — zdalne wykonanie poleceń
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated...
MeetingHub opracowany przez HAMASTAR Technology posiada lukę Missing Authentication, umożliwiającą nieuwierzyt...