CVE-2020-10375
Summary
| CVE | CVE-2020-10375 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-05 20:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template engine product. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Newmediacompany | Smarty | All | All | All | All |
| Application | Newmediacompany | Smarty | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Startseite - Smarty® - Die Praxissoftware | MISC | www.smarty-online.de | Product |
| Advisory X41-2020-005: Insufficient Password Protection in Smarty | X41 D-SEC GmbH | MISC | www.x41-dsec.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.