Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations.
This issue affects Eurosoft Przychodnia software beforeĀ versionĀ 20240417.001 (from that version vulnerability is fixed).
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://cert.pl/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://www.eurosoft.com.pl/eurosoft-przychodnia | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-06-10T11:13:44.453Z
Updated: 2024-06-11T13:30:49.683Z
Reserved: 2024-02-05T13:46:45.179Z
Link: CVE-2024-1228
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-06-10T12:15:09.430
Modified: 2024-06-12T17:54:10.157
Link: CVE-2024-1228
JSON object: View
Redhat Information
No data.
CWE