PT-2018-13169 · Open Dental · Open Dental

Published

2018-12-12

·

Updated

2019-10-09

·

CVE-2018-15719

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Dental versions prior to 18.4
Description The issue allows unauthorized access to database information due to the use of default credentials. Specifically, the mysql database is installed with the default credentials of root and a blank password, potentially exposing all database information to anyone on the network with access to the server.
Recommendations For versions prior to 18.4, update to version 18.4 or later to resolve the issue. As a temporary workaround, consider changing the default database credentials to secure ones, restricting access to the database server, and limiting network access to the server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15719

Affected Products

Open Dental