Cleartext Storage of Sensitive Information in Memory in Easywork Enterprise
Easywork Enterprise 2.1.3.354版本存在内存中明文存储敏感信息的漏洞,激活失败后设备绑定的许可证密钥留在内存中,可被提取用于非法激活软件。 2025-10-23 21:40:36 Author: cxsecurity.com(查看原文) 阅读量:4 收藏

Title: Cleartext Storage of Sensitive Information in Memory in Easywork Enterprise Description: Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a failed activation attempt. The keys can be obtained by attaching a debugger or analyzing the process/memory dump and then they can be used to activate the software on the same machine without purchasing. Source URL: https://github.com/Smarttfoxx/CVE-2025-60791 Source Name/Email: Ivan Oliveira ([email protected]) CVEs: CVE-2025-60791 Software URL: http://easywork.co.id and https://sourceforge.net/projects/easyworkaccounting/


文章来源: https://cxsecurity.com/issue/WLB-2025100012
如有侵权请联系:admin#unsafe.sh