CVE-2024-4996

Use of a hard-coded password for a database administrator account created during Wapro ERPinstallation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERPinstallations.This issue affects Wapro ERP Desktop versions before 8.90.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERT-PLCNA
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H