AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-8774

UNKNOWN · CVSS N/A EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-03-24 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.

CVE
CVE-2024-8774
Severity
UNKNOWN
CVSS
N/A
EPSS
0.32%

Original NVD Description

The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 version received a patch 6.30@a03.9, which removed the vulnerability. Versions 6.20 and 6.25 remain unpatched.