Impact
The flaw in Lenve VHR 1.0‑SNAPSHOT allows an attacker to modify the vhr.sql file to bypass authentication and use default credentials. Based on the description, it is inferred that this can allow unauthenticated remote access. The weakness involves incorrect credential handling as identified by CWE‑1392.
Affected Systems
The affected product is Lenve V‑SNAPSHOT build. No additional version details are provided beyond the snapshot identifier. Users operating this version should verify that they are not using the default configuration or that any exposed interfaces that modify SQL files are secured.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is < 1%, suggesting a very low but non‑zero likelihood that this vulnerability will be exploited. Publicly available exploits exist, based on the description it is inferred that an attacker with access to the application or its web interface could manipulate vhr.sql and log in with default credentials. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment