CyberRota Analysis
AI-GeneratedR-SOFT DMS is vulnerable due to its use of a non-salted nested MD5 hash for storing superadmin credentials, allowing attackers to easily decode these credentials if they obtain the password hash. The inability to change the password without modifying the configuration file exacerbates the risk, making it critical for organizations using this software to upgrade to version v3.17-2000 immediately to mitigate potential unauthorized access. System administrators and security teams should prioritize this vulnerability to protect sensitive administrative functions.
Original NVD Description
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.