Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetric encryption of messages. However, the private RSA key is not only stored on the client but transmitted to the backend, too. Moreover, the key to decrypt the private key is composed of the first 32 bytes of the SHA-512 hash of the user password. But this hash is stored on the backend, too. Therefore, everyone with access to the backend database can read the transmitted secret for symmetric encryption, hence can read the communication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
heinekingmedia StashCat for Android、Web和Desktop 安全漏洞
Vulnerability Description
heinekingmedia StashCat for Android、Web和Desktop都是德国heinekingmedia公司的产品。heinekingmedia StashCat for Android是一款基于Android的企业级通讯软件。heinekingmedia StashCat for Web是基于Web的版本,heinekingmedia StashCat for Desktop是PC端版本。 heinekingmedia StashCat for Android、Web和Desk
CVSS Information
N/A
Vulnerability Type
N/A