Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48241

Опубликовано: 21 мая 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

EPSS

Процентиль: 23%
0.00305
Низкий

8.1 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
github
3 месяца назад

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

EPSS

Процентиль: 23%
0.00305
Низкий

8.1 High

CVSS3

Дефекты

CWE-798