CVE-2018-15719

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
12/12/2018
Last modified:
17/06/2026

Description

Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opendental:opendental:*:*:*:*:*:*:*:* 18.4 (excluding)