VDB
Sign up
HIGH8.8

GHSA-44w5-q257-8428

Exposure of password hashes in notrinos/notrinos-erp

Quick fix

GHSA-44w5-q257-8428 — notrinos/notrinos-erp: upgrade to the fixed version with the command below.

composer require notrinos/notrinos-erp:^0.7

Details

The AP officers account is authorized to Backup and Restore the Database, Due to this he/she can download the backup and see the password hash of the System Administrator account, The weak hash (MD5) of the password can be easily cracked and get the admin password.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/notrinos/notrinos-erp
Introduced in: 0Fixed in: 0.7
Fixcomposer require notrinos/notrinos-erp:^0.7

References