Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85v2-7wpp-wgf5

Опубликовано: 28 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data.

This issue affects Asseco mMedica in versions before 11.9.5.

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data.

This issue affects Asseco mMedica in versions before 11.9.5.

EPSS

Процентиль: 61%
0.0041
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-288

Связанные уязвимости

nvd
3 месяца назад

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data. This issue affects Asseco mMedica in versions before 11.9.5.

EPSS

Процентиль: 61%
0.0041
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-288