An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be accessed directly as well.
References
Link | Resource |
---|---|
https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax | Third Party Advisory |
Configurations
Information
Published : 2021-02-05 12:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-10552
Mitre link : CVE-2020-10552
JSON object : View
CWE
CWE-1188
Insecure Default Initialization of Resource
Products Affected
psyprax
- psyprax