CVE-2024-1346

MEDIUM

LaborOfficeFree <19.10 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-1346. PoCs published by PeterGabaldon.

AI-analyzed exploit summary This repository contains a functional Python script that calculates the MySQL root password for LaborOfficeFree 19.10 by reversing the algorithm used by the software. The README provides detailed technical analysis, including disassembly snippets and the password derivation process.

Description

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.

Exploits (1)

nomisec WORKING POC 2 stars
by PeterGabaldon · poc
https://github.com/PeterGabaldon/CVE-2024-1346

This repository contains a functional Python script that calculates the MySQL root password for LaborOfficeFree 19.10 by reversing the algorithm used by the software. The README provides detailed technical analysis, including disassembly snippets and the password derivation process.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: LaborOfficeFree 19.10
No auth needed
Prerequisites: Access to the target system to extract the license string from memory
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0039
EPSS Percentile 30.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-521
Status published
Products (1)
laborofficefree/laborofficefree 19.10
Published Feb 19, 2024
Tracked Since Feb 18, 2026