Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2022-09-08T15:16:56
Updated: 2024-08-03T10:21:33.284Z
Reserved: 2022-08-01T00:00:00
Link: CVE-2022-37164
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2022-09-08T16:15:08.890
Modified: 2024-11-21T07:14:33.300
Link: CVE-2022-37164
 Redhat
                        Redhat
                    No data.