An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
https://www.ict.co/ | vendor advisory |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5700.php | third party advisory |