CVE-2025-22492

The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La cadena de conexión visible para los usuarios con acceso a la base de datos FRSCore en la máquina virtual Foreseer Reporting Software (FRS) se puede utilizar para obtener acceso administrativo a la base de datos 4crXref. Esta vulnerabilidad se ha resuelto en la última versión 1.5.100 de FRS.

28 Feb 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-28 09:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-22492

Mitre link : CVE-2025-22492

CVE.ORG link : CVE-2025-22492


JSON object : View

Products Affected

No product.

CWE
CWE-922

Insecure Storage of Sensitive Information