Vulnerability Description
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contract Management System Project | Contract Managment System | 2.0 |
Related Weaknesses (CWE)
References
- https://laolisafe.com/contract-management-system2-0ExploitPermissions RequiredThird Party Advisory
- https://laolisafe.com/contract-management-system2-0ExploitPermissions RequiredThird Party Advisory
FAQ
What is CVE-2022-35198?
CVE-2022-35198 is a vulnerability with a CVSS score of 7.5 (HIGH). Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
How severe is CVE-2022-35198?
CVE-2022-35198 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35198?
Check the references section above for vendor advisories and patch information. Affected products include: Contract Management System Project Contract Managment System.