CVE-2022-24860

HIGH

Databasir 1.01 - Use of Hard-coded Cryptographic Key

Title source: llm
STIX 2.1

Description

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at different IP addresses.

Scores

CVSS v3 7.4
EPSS 0.0161
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-321 CWE-798
Status published
Products (1)
databasir_project/databasir 1.0.1
Published Apr 20, 2022
Tracked Since Feb 18, 2026