6.8
CVE-2024-1346
- EPSS 0.32%
- Veröffentlicht 19.02.2024 12:15:45
- Zuletzt bearbeitet 24.03.2025 17:11:55
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Laborofficefree ≫ Laborofficefree Version19.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.542 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| cve-coordination@incibe.es | 6.8 | 2.5 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.