CVE-2021-36718 Information

Description

SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name Employee ID number Working hours etc’) The vulnerabilety has been addressed and fixed on version 11. Default credentials Security miscommunication Sensetive data exposure vulnerability in Synel Reports of SYNEL eharmonynew Synel Reports allows an attacker to log into the system with default credentials. This issue affects: SYNEL eharmonynew Synel Reports 8.0.2 version 11 and prior versions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

https://www.gov.il/en/departments/faq/cve_advisories

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: