Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.
References
Link Resource
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: INCD

Published: 2022-01-25T19:11:08

Updated: 2022-01-25T19:11:08

Reserved: 2022-01-07T00:00:00


Link: CVE-2022-22789

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-25T20:15:08.953

Modified: 2022-02-01T16:18:31.077


Link: CVE-2022-22789

JSON object: View

cve-icon Redhat Information

No data.

CWE