Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://cert.pl/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://dreryk.pl/produkty/gabinet/ | Product |
Configurations
History
12 Jun 2024, 17:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.pl/en/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
References | () https://cert.pl/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
References | () https://dreryk.pl/produkty/gabinet/ - Product | |
CPE | cpe:2.3:a:dreryk:gabinet:*:*:*:*:*:*:*:* | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Dreryk gabinet
Dreryk |
10 Jun 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-10 12:15
Updated : 2024-06-12 17:53
NVD link : CVE-2024-3699
Mitre link : CVE-2024-3699
CVE.ORG link : CVE-2024-3699
JSON object : View
Products Affected
dreryk
- gabinet
CWE
CWE-798
Use of Hard-coded Credentials