Vulnerability Description
HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypassing an unspecified obfuscation technique.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Infohr | Hr Human Resource Information System | 7.9 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/829574US Government Resource
- http://www.kb.cert.org/vuls/id/829574US Government Resource
FAQ
What is CVE-2013-5208?
CVE-2013-5208 is a vulnerability with a CVSS score of 4.1 (MEDIUM). HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypas...
How severe is CVE-2013-5208?
CVE-2013-5208 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5208?
Check the references section above for vendor advisories and patch information. Affected products include: Infohr Hr Human Resource Information System.