CVE Vulnerabilities

CVE-2024-7898

Use of Default Credentials

Published: Aug 17, 2024 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability classified as critical was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This vulnerability affects unknown code of the component Backend. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Weakness

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Affected Software

Name Vendor Start Version End Version
Online_store_management_system Tosei-corporation 4.0.2 (including) 4.0.2 (including)
Online_store_management_system Tosei-corporation 4.0.3 (including) 4.0.3 (including)
Online_store_management_system Tosei-corporation 4.0.4 (including) 4.0.4 (including)

Potential Mitigations

References