Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Juan González

#25822of 53,635
9.8Total CVSS
Vulnerabilities · 1
PT-2023-21549
9.8
2023-10-04
Sage · Sage 200 Spain · CVE-2023-2809
**Name of the Vulnerable Software and Affected Versions** Sage 200 Spain version 2023.38.001 **Description** The issue is related to plaintext credential usage, which could allow a remote attacker to extract SQL database credentials from the DLL application. This could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext. **Recommendations** For Sage 200 Spain version 2023.38.001, consider updating to a newer version that addresses the plaintext credential usage vulnerability to prevent remote attackers from extracting SQL database credentials. As a temporary workaround, restrict access to the DLL application to minimize the risk of exploitation.