An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be accessed directly as well.
References
Link | Resource |
---|---|
https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax | Third Party Advisory |
https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax - Third Party Advisory |
Information
Published : 2021-02-05 20:15
Updated : 2024-11-21 04:55
NVD link : CVE-2020-10552
Mitre link : CVE-2020-10552
CVE.ORG link : CVE-2020-10552
JSON object : View
Products Affected
psyprax
- psyprax
CWE
CWE-1188
Insecure Default Initialization of Resource