PT-2018-1150 · Docutrac · Office Therapy+1
Published
2018-02-09
·
Updated
2019-10-09
·
CVE-2018-5551
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DocuTrac QuicDoc and Office Therapy versions with DTISQLInstaller.exe version 1.6.4.0 and prior
Description
The issue is related to the use of predefined credentials in the DTISQLInstaller.exe executable file. This allows a remote attacker to gain access to the software using the QDMaster, OTMaster, and sa accounts.
Recommendations
For versions with DTISQLInstaller.exe version 1.6.4.0 and prior, consider changing the predefined credentials QDMaster, OTMaster, and sa to secure passwords to prevent unauthorized access.
As a temporary workaround, restrict access to the DTISQLInstaller.exe executable file until a secure version is available.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docutrac Quicdoc
Office Therapy