PT-2022-16934 · Databasir · Databasir
Luckyt0Mat0
·
Published
2022-04-19
·
Updated
2022-04-29
·
CVE-2022-24860
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Databasir version 1.01
Description
Databasir is a team-oriented relational database model document management platform. It has a Use of Hard-coded Cryptographic Key issue. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.
Recommendations
For Databasir version 1.01, as a temporary workaround, consider restricting access to the service background to minimize the risk of exploitation. Avoid using hard-coded cryptographic keys in the login process until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Databasir