Vulnerability in Wapro ERP: Hard-Coded Password Exposure
CVE-2024-4996
9.3CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 18 December 2024
What is CVE-2024-4996?
CVE-2024-4996 represents a significant security vulnerability affecting Wapro ERP Desktop installations prior to version 8.90.0. The issue is rooted in the use of a hard-coded password for the database administrator account, which is consistent across all installations. This allows a malicious actor to potentially exploit the vulnerability to gain unauthorized access, enabling them to retrieve sensitive data embedded within the database. Organizations utilizing affected versions of Wapro ERP should take immediate action to mitigate risks associated with this flaw, such as upgrading to the latest version or implementing access controls where possible.
Affected Version(s)
Wapro ERP Desktop 0 < 8.90.0
