CVE-2024-6118
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.48%
- CWE
- CWE-256
- Published
- 2024-08-05
- Last modified
- 2026-03-13
Affected products
- Hamastar Technology MeetingHub Paperless Meetings
Weakness type
Related vulnerabilities
- CVE-2025-6561 — Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
- CVE-2025-6560 — Sapido Wireless Router - Exposure of Sensitive Information
- CVE-2025-5893 — Honding Technology Smart Parking Management System - Exposure of Sensitive Information
- CVE-2025-34210 — Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords
- CVE-2025-15113 — Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload
- CVE-2025-2500 — A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an
- CVE-2020-5374 — Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain
- CVE-2024-3622 — Mirror-registry: plain-text default csrf secret key