Vulnerability Description
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eurosoft | Przychodnia | < 20240417.001 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://www.eurosoft.com.pl/eurosoft-przychodniaProduct
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://www.eurosoft.com.pl/eurosoft-przychodniaProduct
FAQ
What is CVE-2024-1228?
CVE-2024-1228 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This ...
How severe is CVE-2024-1228?
CVE-2024-1228 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-1228?
Check the references section above for vendor advisories and patch information. Affected products include: Eurosoft Przychodnia.