vendor:
Mikogo
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Local Credentials Disclosure
200
CWE
Product Name: Mikogo
Affected Version From: 5.4.1.160608
Affected Version To: 5.4.1.160608
Patch Exists: YES
Related CWE: N/A
CPE: a:snapview_gmbh:mikogo
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Mikogo 5.4.1.160608 Local Credentials Disclosure
Mikogo is vulnerable to local credentials disclosure, the supplied password is stored as a MD5 hash format in memory process. A potential attacker could reveal the supplied password hash and re-use it or store it via the configuration file in order to gain access to the account.
Mitigation:
Ensure that the Mikogo software is updated to the latest version.