Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfwr-xp7c-5pq8

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.

JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.

EPSS

Процентиль: 31%
0.00115
Низкий