Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
Summary
The ESAFENET CDG 3 Document Management System, a product primarily for the Chinese market, has been found to have basic security vulnerabilities including SQL Injection, XSS, and default passwords. This is not the first time ESAFENET CDG has been observed in scanning activities, particularly after a cross-site scripting vulnerability was disclosed.
IFF Assessment
The discovery of critical vulnerabilities like SQL Injection and weak default credentials in a document management system poses a significant risk to data security and privacy.
Severity
This score reflects a combination of vulnerabilities: SQL Injection (high impact for data theft/manipulation) and weak default passwords (high exploitability, allowing unauthorized access). The potential for data leakage prevention product compromise significantly raises the risk.
Defender Context
Defenders should be aware of ongoing scanning for systems with weak credentials and common web vulnerabilities like SQL Injection and XSS. Organizations using or considering document management systems should prioritize robust security configurations, regular patching, and strong password policies.