Impact
mpGabinet was found to assign too many database privileges to the user account it relies on. An attacker who can observe a running instance of the application can read the database credentials from the process memory. Although reading memory may be expected in some scenarios, the exposed credentials provide administrative rights to the database, giving the attacker permissions far beyond normal application functionality. This represents a privilege escalation vulnerability consistent with CWE‑250.
Affected Systems
The vulnerability affects BinSoft’s mpGabinet software version 23.12.19 and all earlier releases.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The exploit probability is not publicly available, and the issue is not listed in CISA’s KEV catalog. The most likely attack path involves an attacker gaining local or remote access to a running application instance and probing the process memory to retrieve database credentials, which is then leveraged to obtain administrative database actions. Adequate hardening of process visibility and privilege reductions can mitigate this risk.
OpenCVE Enrichment