CVE-2024-36049 describes a critical vulnerability in Aptos Wisal payroll accounting software prior to version 7.1.6, where the Windows client utilizes hardcoded credentials to retrieve all usernames and passwords from the database server over an unencrypted connection. This flaw allows attackers performing a machine-in-the-middle (MitM) attack to gain read and write access to sensitive PII and payroll data, as well as impersonate legitimate users. Rated 6.5 MEDIUM, the vulnerability has a low attack complexity and high impact on confidentiality, but currently shows no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.