Executive brief
The Prog Management System, a business management platform developed by PROG MIS, contains a critical security flaw that exposes sensitive system credentials. An unauthorized person can access a specific page on the system to view the database username and password. This could allow an attacker to gain full control over the organization's database, leading to the theft of sensitive data or a complete service shutdown.
Technical details
An Exposure of Sensitive Information vulnerability (CWE-497) exists in the PROG MIS Prog Management System. The flaw is located in a specific, publicly accessible page that inadvertently displays the system's database account and password. An unauthenticated remote attacker can exploit this by navigating to the affected URL, requiring no special privileges or user interaction. Successful exploitation grants the attacker the credentials necessary to access the backend database directly, potentially leading to full data exfiltration or unauthorized modification of records. Users are advised to contact the vendor for patching information.
Affected products
- PROG MIS (博格資訊管理顧問) Prog Management System All versions affected
Timeline
- 2026-07-06: advisory: Advisory published by TWCERT/CC and NVD