Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
History

Wed, 18 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 11:45:00 +0000

Type Values Removed Values Added
Description Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
Title Hardcoded Password in Wapro ERP Desktop
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:I/V:C/RE:M/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2024-12-18T11:37:23.937Z

Updated: 2024-12-18T14:47:34.643Z

Reserved: 2024-05-16T10:39:01.510Z

Link: CVE-2024-4996

cve-icon Vulnrichment

Updated: 2024-12-18T14:47:09.246Z

cve-icon NVD

Status : Received

Published: 2024-12-18T12:15:10.120

Modified: 2024-12-18T15:15:12.210

Link: CVE-2024-4996

cve-icon Redhat

No data.