Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-3854

Опубликовано: 03 дек. 2018
Источник: nvd
CVSS3: 7.1
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:intuit:quicken_2018:5.2.2:*:*:*:deluxe:macos:*:*

EPSS

Процентиль: 18%
0.00056
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.1
github
больше 3 лет назад

An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.

EPSS

Процентиль: 18%
0.00056
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-200