Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
Vulnerability Description
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
Soroush IM Desktop App 安全漏洞
Vulnerability Description
Soroush IM Desktop App是伊朗Soroush公司的一款跨平台即时通讯客户端。 Soroush IM Desktop App 0.17.0版本存在安全漏洞,该漏洞源于身份验证绕过,可能导致本地攻击者通过注入使用恒定加密密钥预加密的数据库条目来移除密码。
CVSS Information
N/A
Vulnerability Type
N/A