IceHrm prima 23.0.1.OS ha un uso rischioso di una password hash in una richiesta. |
https://github.com/gamonoid/icehrm/commit/025a8283ab5d679ff99a6b82398e4c8efed1ad9d https://github.com/gamonoid/icehrm/releases/tag/v23.0.1.OS https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12420 |
Vulnerabilità: CVE-2018-12420
