Impact
The flaw is an improper access control in the Hashtopolis server web‑interface chunk activity component. It allows any user account that has been created, even with basic privileges, to read every cracked hash stored by the instance. The weakness maps to CWE‑639, which involves improper handling of authorization data and can lead to confidentiality compromise. The vulnerability is not a remote code execution or denial of service; it is strictly a data disclosure issue.
Affected Systems
The affected product is Hashtopolis server. Versions earlier than 0.14.8 are vulnerable. The issue was resolved in release 0.14.8, which removes the ability for non‑privileged users to view all hashes.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to loss. The EPSS score of less than 1% suggests that exploitation is currently rare the CISA KEV catalog. Likely attack vector is an authenticated session: once a to the chunk activity page and retrieve hash data. The attacker needs no special privileges beyond account creation and cannot exploit the vulnerability from the outside. The overall risk is therefore significant for any environment where the server holds valuable hash data, but the likelihood of exploitation remains low at present.
OpenCVE Enrichment