CVE-2023-37468

MEDIUM

Feedbacksystem 1.5.0-1.9.1 - Cleartext Storage of Sensitive Information in LDAP Login

Title source: llm
STIX 2.1

Description

Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP users password is passed unencrypted in the LoginController.scala and stored in the database when logging in for the first time. Users using only local login or the cas login are not affected. This issue has been patched in version 1.19.2.

Scores

CVSS v3 6.0
EPSS 0.0016
EPSS Percentile 5.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
thm/feedbacksystem 1.5.0 - 1.9.2
Published Jul 13, 2023
Tracked Since Feb 18, 2026