PT-2022-16934 · Databasir · Databasir

Luckyt0Mat0

·

Published

2022-04-19

·

Updated

2022-04-29

·

CVE-2022-24860

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Databasir version 1.01
Description Databasir is a team-oriented relational database model document management platform. It has a Use of Hard-coded Cryptographic Key issue. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.
Recommendations For Databasir version 1.01, as a temporary workaround, consider restricting access to the service background to minimize the risk of exploitation. Avoid using hard-coded cryptographic keys in the login process until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24860
GHSA-9PRP-5JC9-JPGG

Affected Products

Databasir