PT-2018-1150 · Docutrac · Office Therapy+1

Published

2018-02-09

·

Updated

2019-10-09

·

CVE-2018-5551

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DocuTrac QuicDoc and Office Therapy versions with DTISQLInstaller.exe version 1.6.4.0 and prior
Description The issue is related to the use of predefined credentials in the DTISQLInstaller.exe executable file. This allows a remote attacker to gain access to the software using the QDMaster, OTMaster, and sa accounts.
Recommendations For versions with DTISQLInstaller.exe version 1.6.4.0 and prior, consider changing the predefined credentials QDMaster, OTMaster, and sa to secure passwords to prevent unauthorized access. As a temporary workaround, restrict access to the DTISQLInstaller.exe executable file until a secure version is available.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00587
CVE-2018-5551

Affected Products

Docutrac Quicdoc
Office Therapy