vendor:
PortableKanban
by:
rootabeta
N/A
CVSS
N/A
Encrypted Password Retrieval
CWE
Product Name: PortableKanban
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 x64. Exploit likely works on all OSs that PBK runs on.
2021
PortableKanban 4.3.6578.38136 – Encrypted Password Retrieval
PortableKanBan stores credentials in an encrypted format. Reverse engineering the executable allows an attacker to extract credentials from local storage. Provide this program with the path to a valid PortableKanban.pk3 file and it will extract the decoded credentials.
Mitigation:
Unknown