PT-2021-21322 · Synel · Synel Reports+1
Published
2021-12-08
·
Updated
2023-08-08
·
CVE-2021-36718
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SYNEL eharmonynew versions prior to 11
Synel Reports versions prior to 11
Synel Reports version 8.0.2
Description
The issue allows an attacker to log in to the system with default credentials and export a report of the eharmony system with sensitive data, including employee name, employee ID number, and working hours. This is due to default credentials and security miscommunication, leading to sensitive data exposure vulnerability in Synel Reports.
Recommendations
For SYNEL eharmonynew versions prior to 11, update to version 11 or later to address the issue.
For Synel Reports versions prior to 11, update to version 11 or later to address the issue.
For Synel Reports version 8.0.2, update to version 11 or later to address the issue.
As a temporary workaround, consider changing the default credentials to prevent unauthorized access until a patch is applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synel Eharmonynew
Synel Reports