CVE-2026-6500
Plaintext Password Storage in OpenConcerto
Publication date: 2026-05-04
Last updated on: 2026-05-04
Assigner: TCS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ilm_informatique | openconcerto | 1.7.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-256 | The product stores a password in plaintext within resources such as memory or files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the storage of passwords in plaintext within the ILM Informatique OpenConcerto software, specifically version 1.7.5. Because passwords are stored without encryption or hashing, an attacker or unauthorized user with access to the system can retrieve sensitive embedded data directly.
How can this vulnerability impact me? :
The impact of this vulnerability is that sensitive password information can be exposed to unauthorized parties. This exposure can lead to unauthorized access to accounts or systems, potentially compromising the confidentiality and security of data managed by OpenConcerto.