Junglewise Threat Intelligence

CVE-2025-52164: Agorum core open plaintext credential storage in installation datasheet

CVE-2025-52164 · Severity: high · CVSS 8.2 · Published 2025-07-18

Executive brief

Agorum core open, an enterprise content management system used for document management and workflow automation, was found to store administrative and database credentials in a plaintext file. During installation, the system creates a datasheet containing sensitive passwords for the main administrator, demo accounts, and the database. If an unauthorized person gains access to the server's file system, they could use these credentials to take full control of the document management system and its underlying data.

Technical details

Agorum core open (specifically version 11.9.1.3-1857) suffers from plaintext storage of sensitive credentials (CWE-256). During the installation process, the system generates a file named 'agorum-core-datasheet.txt' in the 'agorumcore/doc' directory. This file contains the plaintext passwords for the 'roi' (Mainadmin), 'demo', and 'root' (MySQL database) users. An attacker with local file system access can read this file to obtain high-privileged credentials, leading to full system compromise. The vendor has addressed this in versions 11.9.2 and 11.10.1.

Affected products

  • Agorum Software GmbH Agorum core open 11.9.1.3-1857 and earlier

Timeline

  • 2025-05-05: disclosed: First contact with vendor
  • 2025-05-15: patched: Vendor fixed vulnerability in cloud instances
  • 2025-05-30: patched: Vendor released fixed versions 11.9.2 and 11.10.1
  • 2025-06-27: advisory: Initial advisory publication by usd HeroLab
  • 2025-07-18: advisory: NVD publication date

References