Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m3w-vxfv-jm2w

Опубликовано: 21 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

EPSS

Процентиль: 23%
0.00305
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

EPSS

Процентиль: 23%
0.00305
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-798