PT-2026-64377 · Syspass · Syspass
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sysPass versions prior to 3.2.12
Description
Authenticated users possessing the
PUBLICLINK CREATE profile flag can trigger unauthorized decryption and persistent storage of any vault account password. This occurs due to missing AccountAcl checks during the public link creation process. An attacker can call the 'saveCreateFromAccountAction' endpoint, causing the getDataForLink() function in AccountService to load arbitrary target accounts without AccountFilterUser restrictions. This process decrypts credentials using the session master key and serializes cleartext passwords into the Vault storage within the PublicLink database row, which may allow unauthenticated retrieval if the resulting link hash is obtained.Recommendations
Update to a version newer than 3.2.11.
Restrict the use of the
PUBLICLINK CREATE profile flag for users until the update is applied.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syspass