CVE-2022-37857

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
08/09/2022
Last modified:
08/08/2023

Description

bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hauk_project:hauk:1.6.1:*:*:*:*:*:*:*