HIGH8.8
GHSA-44w5-q257-8428
Exposure of password hashes in notrinos/notrinos-erp
Quick fix
GHSA-44w5-q257-8428 — notrinos/notrinos-erp: upgrade to the fixed version with the command below.
composer require notrinos/notrinos-erp:^0.7Details
The AP officers account is authorized to Backup and Restore the Database, Due to this he/she can download the backup and see the password hash of the System Administrator account, The weak hash (MD5) of the password can be easily cracked and get the admin password.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/notrinos/notrinos-erp
Introduced in:
0Fixed in: 0.7Fix
composer require notrinos/notrinos-erp:^0.7