CVE-2022-25577

CRITICAL

alf-banco < 8.2.5 - Use of Hard-coded Credentials for SQLite Database Encryption

Title source: llm
STIX 2.1

Description

ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0120
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-798
Status published
Products (1)
alf-banco/alf-banco 8.2.3 - 8.2.5
Published Mar 25, 2022
Tracked Since Feb 18, 2026