ReadyDesk 9.1 allows local users to determine cleartext SQL Server credentials by reading the SQL_Config.aspx file and decrypting data with a hardcoded key in the ReadyDesk.dll file. <a href"http://cwe.mitre.org/data/definitions/611.html">CWE-321: Use of Hard-coded Cryptographic Key</a>
Publication date: Sat, 27 Aug 2016 00:59:00 +0000