PT-2021-9089 · Scytl · Scytl Svote

Anthony Schneiter

+1

·

Published

2021-02-27

·

Updated

2021-03-05

·

CVE-2019-25021

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Scytl sVote version 2.1
Description An issue was discovered due to the implementation of the database manager, allowing an attacker to access the OrientDB by providing admin as the admin password. A different password cannot be set because of the implementation in code.
Recommendations For Scytl sVote version 2.1, consider changing the default admin password to a unique and strong password as soon as possible. However, since the code implementation does not allow setting a different password, as a temporary workaround, restrict access to the OrientDB to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25021

Affected Products

Scytl Svote