Executive brief
R-SOFT DMS, a document management system, uses an insecure method to store administrative passwords. Because these passwords are protected by weak encryption without modern safeguards, an attacker who gains access to the password data can easily recover the original credentials. This could lead to a full takeover of the system, especially since the administrative password cannot be changed through the standard user interface.
Technical details
R-SOFT DMS is vulnerable to the use of a weak cryptographic hash (CWE-328) for superadministrator credentials. The system utilizes a nested MD5 hash without a salt, making it highly susceptible to rainbow table attacks or brute-force decryption if the hash is exposed (e.g., via database access or configuration file leakage). Furthermore, the superadministrator password is hardcoded in a way that it cannot be updated via the application interface, requiring manual modification of configuration files. This issue is resolved in version v3.17-2000.
Affected products
- R-SOFT SERWIS DMS All versions prior to v3.17-2000
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory