CVE-2022-22789

Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
References
Link Resource
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:charactell:formstorm:9.00.065:*:*:*:enterprise:*:*:*

History

01 Feb 2022, 16:18

Type Values Removed Values Added
CPE cpe:2.3:a:charactell:formstorm:9.00.065:*:*:*:enterprise:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
References (MISC) https://www.gov.il/en/departments/faq/cve_advisories - (MISC) https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory
CWE CWE-312

25 Jan 2022, 20:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-25 20:15

Updated : 2024-02-04 22:08


NVD link : CVE-2022-22789

Mitre link : CVE-2022-22789

CVE.ORG link : CVE-2022-22789


JSON object : View

Products Affected

charactell

  • formstorm
CWE
CWE-312

Cleartext Storage of Sensitive Information