Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27932 | Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file. |
Fixes
Solution
A patch was released, Charactell - FormStorm Enterprise version 9.00.066
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-08-03T03:21:49.165Z
Reserved: 2022-01-07T00:00:00
Link: CVE-2022-22789
No data.
Status : Modified
Published: 2022-01-25T20:15:08.953
Modified: 2024-11-21T06:47:27.307
Link: CVE-2022-22789
No data.
OpenCVE Enrichment
No data.
EUVD