An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be accessed directly as well.
References
Link | Resource |
---|---|
https://www.x41-dsec.de/lab/advisories/x41-2020-002-psyprax | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-02-05 20:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-10552
Mitre link : CVE-2020-10552
CVE.ORG link : CVE-2020-10552
JSON object : View
Products Affected
psyprax
- psyprax
CWE
CWE-1188
Initialization of a Resource with an Insecure Default