VYPR

Archiving Backend

Sign in to watch

by Telemessage

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-477290.120.04KEVMay 8, 2025The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
CVE-2025-477300.000.00May 8, 2025The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.