PT-2017-6781 · Mysql Server · Xsuite
Martin Schobert
·
Published
2017-09-25
·
Updated
2018-10-09
·
CVE-2015-4669
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xsuite versions 2.x
Description
The issue concerns the MySQL "root" user in the affected software, which does not have a password set. This allows local users to access databases on the system.
Recommendations
For Xsuite versions 2.x, set a strong password for the MySQL "root" user to prevent unauthorized access to databases.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xsuite