Impact
The vulnerability is a hard‑coded credential issue in the Settings Handler of SxDevOps. The manipulation of backend/sxdevops/settings.py exposes sensitive authentication information, which an attacker can read or override. This flaw aligns with CWE‑259 (Hard‑coded Password) and CWE‑798 (Using Hard‑coded Secrets). Because credentials can be exposed or altered, an attacker may gain unauthorized access to the system or elevate privileges.
Affected Systems
The affected product is aiyiyi121:SxDevOps, specifically versions 1.0 and 1.1. No other vendor or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. EPSS for this vulnerability is not available, so the precise likelihood of exploitation cannot be quantified. The vendor notes that the attack may be performed from remote, suggesting that legitimate remote users could trigger the flaw. The issue is not listed in the CISA KEV catalog, implying no known deployed exploits in the wild yet, but the presence of hard‑coded credentials remains a critical concern.
OpenCVE Enrichment