CyberRota Analysis
AI-GeneratedThe Hashtopolis server web-interface prior to version 0.14.8 has an improper access control vulnerability that permits any user account to access all cracked hashes within the server instance. This exposure could lead to unauthorized disclosure of sensitive data, potentially compromising the security of password hashes. Organizations using affected versions should prioritize this issue to prevent unauthorized access to sensitive information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.