LaborOfficeFree是LaborOfficeFree公司的一个免费的 Turnos 管理和 Presencia 控制软件。 LaborOfficeFree 19.10版本存在安全漏洞,该漏洞源于允许攻击者使用两个常量计算MySQL数据库的root密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LaborOfficeFree | LaborOfficeFree | 19.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants. | https://github.com/PeterGabaldon/CVE-2024-1346 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-1344 | 6.8 MEDIUM | Encrypted database credentials in LaborOfficeFree |
| CVE-2024-1345 | 6.8 MEDIUM | Weak MySQL database root password in LaborOfficeFree |
| CVE-2024-1343 | 4.7 MEDIUM | Weak permission vulnerability in LaborOfficeFree |
No comments yet