CVE Database
/

CVE-2024-8774

Back to search

CVE-2024-8774

Published: Mar 24, 2025

Modified: Mar 24, 2025

PUBLISHED

Description

The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 version received a patch [email protected], which removed the vulnerability. Versions 6.20 and 6.25 remain unpatched.

VendorProductVersions

Simple SA

SIMPLE.ERP

affected
6.20 - < [email protected]

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now