Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q75-fhmp-pjmr

Опубликовано: 06 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

EPSS

Процентиль: 0%
0.00007
Низкий

7.1 High

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 7.1
nvd
4 дня назад

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

EPSS

Процентиль: 0%
0.00007
Низкий

7.1 High

CVSS3

Дефекты

CWE-321