peter bassill · operator
$ cve CVE-2015-3001 JSON

CVE-2015-3001 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.8% (pctl 94)

Patch early

A public exploit exists.

Description

SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS6.78% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploityes
Published2015-06-08
Last modified2026-06-17

Affected (1)

VendorProduct
sysaidsysaid

Public exploits

SourceTitleDate
exploit-dbSysAid Help Desk 14.4 - Multiple Vulnerabilities2015-06-10

References

→ the Explorer  ·  watch your stack  ·  NVD