CVE-2017-11131 Information
Feb 14, 2021
cve
Description
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android through 0.0.80w for Web and through 0.0.86 for Desktop. For authentication the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover only the first 32 bytes of the hash are used. This allows for easy dictionary and rainbow-table attacks if an attacker has access to the password hash.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://seclists.org/fulldisclosure/2017/Jul/90
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.9
Share on: