Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjg3-g5mq-q5qp

Опубликовано: 24 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.1

Описание

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.

This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.

This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3

EPSS

Процентиль: 6%
0.00021
Низкий

8.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.1
nvd
3 месяца назад

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3

EPSS

Процентиль: 6%
0.00021
Низкий

8.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-798