Back to all
2024-08-05

Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Password

ZUSOART ID
ZA-2024-03
CVE ID
CVE-2024-6118
Vulnerability Type
CWE-256: Plaintext Storage of a Password
CVSS 4.0 Base
9.3
Description

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.

Vendor
Hamastar Technology
Product
Category
Version affected
MeetingHub Paperless Meetings
2021
Mitigations

Contact Hamastar Technology for version updates.

Release date
2024-08-05
Credit

Yen Chun Shen (YC Shen) of ZUSO ART