WorkSimple contains a flaw that may lead to an unauthorized password exposure. It is possible for a remote attacker to gain access to encrypted passwords when making a direct request for data/usr.txt.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Public,
Exploit Commercial
Disclosure:
Vendor Verified,
Third-party Verified,
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 1.3.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.