ZeroHour

CVE-2017-9615

CVSS 3.0
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.

Vendors
cognito
Products
moneyworks
Weakness
CWE-532, CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.