Executive brief
The ERP App developed by PROG MIS contains hard-coded login credentials. This allows an unauthorized person to remotely log into the system, view the application's source code, and steal database usernames and passwords. This could lead to a total compromise of sensitive business data and the underlying database.
Technical details
The PROG MIS ERP App suffers from a Use of Hard-coded Credentials vulnerability (CWE-798). An unauthenticated remote attacker can exploit these static credentials to gain unauthorized access to the application. Once logged in, the attacker can view the application's source code and extract sensitive configuration details, including database account names and passwords. The vulnerability is assigned a CVSS 3.1 score of 9.8, indicating high impact on confidentiality, integrity, and availability. Users are advised to contact the vendor for patching information.
Affected products
- PROG MIS (博格資訊管理顧問) ERP App All versions affected
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory