Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 18 Dec 2024 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0. | |
Title | Hardcoded Password in Wapro ERP Desktop | |
Weaknesses | CWE-798 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-12-18T11:37:23.937Z
Updated: 2024-12-18T14:47:34.643Z
Reserved: 2024-05-16T10:39:01.510Z
Link: CVE-2024-4996
Vulnrichment
Updated: 2024-12-18T14:47:09.246Z
NVD
Status : Received
Published: 2024-12-18T12:15:10.120
Modified: 2024-12-18T15:15:12.210
Link: CVE-2024-4996
Redhat
No data.