PT-2024-1929 · Unknown · Mysql Server+1
Alejandro Baño Andrés
+3
·
Published
2024-02-08
·
Updated
2024-02-20
·
CVE-2024-1345
CVSS v3.1
6.8
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LaborOfficeFree version 19.10
Description
The issue is related to weak password requirements in LaborOfficeFree, which can be exploited to perform a brute force attack. This allows an attacker to easily discover the root password of the MySQL database.
Recommendations
For version 19.10, update the MySQL database root password to a stronger one to prevent brute force attacks. As a temporary workaround, consider restricting access to the MySQL database to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Laborofficefree
Mysql Server