SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-40295

The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

MEDIUM 4.9EPSS 0.39%

Does this matter?

Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.

Description

The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.39% probability · 33th percentile
CISA KEV
Not listed
Weakness
CWE-916, CWE-311
Affected
phppointofsale/php point of sale
Source
vdp@themissinglink.com.au

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.