vendor:
Ingenium Learning Management System
by:
Brian Enigma
3.3
CVSS
MEDIUM
Weak Algorithm Vulnerability
327
CWE
Product Name: Ingenium Learning Management System
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Ingenium Learning Management System Weak Algorithm Vulnerability
Ingenium Learning Management System uses a weak algorithm to hash user and administrative credentials. Passwords may be trivially obtained by reversing the password hash. An attacker must be able to gain unauthorized access to the password hashes for this issue to be exploited. This may be achieved by taking advantage of the issue described in Bugtraq ID 5969. Hashed user credentials will also be stored in the database, and may potentially be retrieved by an attacker with the ability to construct or influence SQL queries.
Mitigation:
Ensure that the Ingenium Learning Management System is configured to use a strong algorithm to hash user and administrative credentials.