Описание
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
Ссылки
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:xerox:xmpie_ustore:12.3.7244.0:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00301
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
EPSS
Процентиль: 53%
0.00301
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287