CVE-2024-36049

MEDIUM

Aptos Wisal Payroll Accounting <7.1.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable information (PII) and especially payroll data and the ability to impersonate legitimate users with respect to the audit log.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Published May 24, 2024
Tracked Since Feb 18, 2026