EUVD-2025-31158
ID: EUVD-2025-31158
Severity: high
CVSS v4: Not provided
CVSS v3: 7.3 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
CWE: None listed
Source: ENISA
Description
This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.
Timestamps
- Normalized:
- Last updated:
References
No references provided.