CVE-2024-1346
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.39%
- CWE
- CWE-521
- Published
- 2024-02-19
- Last modified
- 2026-03-13
Affected products
- LaborOfficeFree LaborOfficeFree
Weakness type
Related vulnerabilities
- CVE-2026-85216 — MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-19293 — SMP security request
- CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration
- CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy
- CVE-2026-35097 — Weak Password Requirements in KTM System e-BOK
- CVE-2026-11493 — Tenda AC15 Samba smb.conf weak password
- CVE-2024-40684 — IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism
- CVE-2026-9394 — Besen BS20 EV Charging Station Bluetooth Low Energy weak password