NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://github.com/0xfml/poc/blob/main/NCH/ReflectCRM_3.01_CC.md | third party advisory exploit |
https://www.nchsoftware.com/crm/index.html | product |