Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-10-04T10:49:56.429Z

Updated: 2024-08-02T06:33:05.522Z

Reserved: 2023-05-19T10:54:17.589Z

Link: CVE-2023-2809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-10-04T11:15:10.223

Modified: 2023-12-19T15:15:08.230

Link: CVE-2023-2809

cve-icon Redhat

No data.