CVE-2019-25021

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
27/02/2021
Last modified:
05/03/2021

Description

An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A different password cannot be set because of the implementation in code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scytl:secure_vote:2.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools