Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p74r-mvhv-7jx7

Опубликовано: 15 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations.

This issue affects ERP XL: from 2020.2.2 through 2023.2.

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations.

This issue affects ERP XL: from 2020.2.2 through 2023.2.

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from 2020.2.2 through 2023.2.

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

Дефекты

CWE-798