Laborofficefree is a focused office management application whose vulnerability profile centers on authentication and access-control weaknesses, including weak password requirements, hard-coded credentials, improper access restrictions, and insufficient rate-limiting on authentication attempts. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laborofficefree over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1344CRITICAL Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of | Feb 19, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-1346MEDIUM Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by Labor | Feb 19, 2024 | 5.5 | 18 | NO | NO |
CVE-2024-1345MEDIUM Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root passw | Feb 19, 2024 | 5.5 | 17 | NO | NO |
CVE-2024-1343MEDIUM A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directo | Feb 19, 2024 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laborofficefree.
Media articles that mention a CVE ID that affects a product developed by Laborofficefree — matched by CVE ID, not by vendor name.