Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
The product uses a hard-coded, unchangeable cryptographic key.
Link | Tags |
---|---|
https://github.com/mojibake-dev/hMailEnum | exploit third party advisory |
https://github.com/hmailserver/hmailserver | product |
https://github.com/mojibake-dev/mojibake-CVE/blob/main/hMailServer/CVE-2025-52373.md | exploit third party advisory |