MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://github.com/ifmacedo/mconnect/blob/main/IDCE-ClearTextStorage | exploit |
https://www.linkedin.com/pulse/armazenamento-inseguro-idce-mv-iran-macedo | third party advisory exploit |
https://mv.com.br/pt/blog/microdata-integra-novo-modulo-cockpit-ao-ris-idce | press/media coverage |