CVE-2025-52373
4.6MEDIUMUse of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
Опубликовано: 7/21/2025Обновлено: 8/7/2025
Описание
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
ИИ-АнализНа базе ИИ
Затронутые продукты
hmailserverhmailserver
5.6.9
hmailserverhmailserver
5.8.6
Ссылки
- https://github.com/hmailserver/hmailserverProduct
- https://github.com/mojibake-dev/hMailEnumExploitThird Party Advisory
- https://github.com/mojibake-dev/mojibake-CVE/blob/main/hMailServer/CVE-2025-52373.mdExploitThird Party Advisory