Filtered by CWE-759
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-21253 1 Onlinevotingsystem Project 1 Onlinevotingsystem 2022-10-24 5.3 Medium
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Without a salt, it is much easier for attackers to pre-compute the hash value using dictionary attack techniques such as rainbow tables to crack passwords. This problem is fixed and published in version 1.1.2. A long randomly generated salt is added to the password hash function to better protect passwords stored in the voting system.
CVE-2020-25164 1 Bbraun 2 Datamodule Compactplus, Spacecom 2022-04-21 7.5 High
A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
CVE-2020-16244 1 Ge 1 Asset Performance Management Classic 2021-11-22 7.2 High
GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.