vendor:
EDMS
by:
Burov Konstantin
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: EDMS
Affected Version From: Detrix 1.2.3.1505
Affected Version To: Detrix 1.2.3.1505
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2019
Detrix EDMS cleartext user password remote SQLI exploit
This exploit allows an attacker to gain access to the Detrix EDMS system by exploiting a SQL injection vulnerability and decrypting the user password. The exploit sends a malicious SQL query to the target host, which is then used to extract the encrypted user password from the database. The encrypted password is then decrypted using a key from the Detrix EDMS system and the clear-text password is revealed.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all user passwords are stored in an encrypted format and that the encryption key is not accessible to attackers.