Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations.
This issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed).
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://cert.pl/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://www.eurosoft.com.pl/eurosoft-przychodnia | Product |
Configurations
History
12 Jun 2024, 17:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.pl/en/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
References | () https://cert.pl/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
References | () https://www.eurosoft.com.pl/eurosoft-przychodnia - Product | |
First Time |
Eurosoft
Eurosoft przychodnia |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:eurosoft:przychodnia:*:*:*:*:*:*:*:* | |
Summary |
|
10 Jun 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-10 12:15
Updated : 2024-06-12 17:54
NVD link : CVE-2024-1228
Mitre link : CVE-2024-1228
CVE.ORG link : CVE-2024-1228
JSON object : View
Products Affected
eurosoft
- przychodnia
CWE
CWE-798
Use of Hard-coded Credentials