CVE-2020-10375

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
05/02/2021
Last modified:
21/07/2021

Description

An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template engine product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:newmediacompany:smarty:*:*:*:*:*:*:*:* 9.10 (excluding)