The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this
string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.
string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5500 | The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Feb 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS. | |
| Title | Insecure storage of connection strings in FRS | |
| Weaknesses | CWE-922 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2025-02-28T13:14:41.526Z
Reserved: 2025-01-07T09:41:16.734Z
Link: CVE-2025-22492
Updated: 2025-02-28T13:14:36.271Z
Status : Received
Published: 2025-02-28T09:15:12.680
Modified: 2025-02-28T09:15:12.680
Link: CVE-2025-22492
No data.
OpenCVE Enrichment
No data.
EUVD