Description
Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
Published: 2022-01-25
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

A patch was released, Charactell - FormStorm Enterprise version 9.00.066

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-27932 Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
History

No history.

Subscriptions

Charactell Formstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2024-08-03T03:21:49.165Z

Reserved: 2022-01-07T00:00:00.000Z

Link: CVE-2022-22789

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-25T20:15:08.953

Modified: 2024-11-21T06:47:27.307

Link: CVE-2022-22789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses