MEDIUM · 4.1

CVE-2013-5208

HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypas...

Vulnerability Description

HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypassing an unspecified obfuscation technique.

CVSS Score

4.1

MEDIUM

AV:L/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
InfohrHr Human Resource Information System7.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-5208?

CVE-2013-5208 is a vulnerability with a CVSS score of 4.1 (MEDIUM). HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypas...

How severe is CVE-2013-5208?

CVE-2013-5208 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5208?

Check the references section above for vendor advisories and patch information. Affected products include: Infohr Hr Human Resource Information System.