CVE-2022-40295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
31/10/2022
Last modified:
25/10/2023

Description

<br /> The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools