The password of a web user in "Sante PACS Server.exe" is...
High severity
Unreviewed
Published
Mar 13, 2025
to the GitHub Advisory Database
•
Updated Mar 13, 2025
Description
Published by the National Vulnerability Database
Mar 13, 2025
Published to the GitHub Advisory Database
Mar 13, 2025
Last updated
Mar 13, 2025
The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte
References