PT-2024-27234 · Unknown · Dreryk Gabinet

Published

2024-06-10

·

Updated

2025-10-03

·

CVE-2024-3699

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions drEryk Gabinet versions 7.0.0.0 through 9.17.0.0
Description The issue is related to the use of a hard-coded password to access the patients' database, allowing an attacker to retrieve sensitive data. This password is uniform across all drEryk Gabinet installations.
Recommendations For versions 7.0.0.0 through 9.17.0.0, consider changing the hard-coded password to a unique and secure password for each installation as a temporary workaround. Restrict access to the patients' database to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-3699

Affected Products

Dreryk Gabinet