SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
References
Configurations
Information
Published : 2015-06-08 07:59
Updated : 2018-10-09 12:56
NVD link : CVE-2015-3001
Mitre link : CVE-2015-3001
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
sysaid
- sysaid