CVE-2025-13776

EUVD-2025-208095
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.

This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
finkafinka-faktura
𝑥
< 18.3
finkafinka-fk
𝑥
< 18.5
finkafinka-kpr
𝑥
< 16.6
finkafinka-magazyn
𝑥
< 8.3
finkafinka-place
𝑥
< 13.4
finkafinka-stw
𝑥
< 12.3
𝑥
= Vulnerable software versions