molfar_audit / Rules / CFG003
CFG003 Database user is root or has no password
critical Server config
mysql_connection_string uses the root user or an empty password.
Why it matters
Any SQL injection in any resource then gets full control of every database on the host. A passwordless database is one firewall mistake away from being public. The report never shows the connection string itself.
How to fix
Create a dedicated database user with rights only on the server database and a strong password.
Fixed
CREATE USER 'fivem'@'localhost' IDENTIFIED BY 'long-random-password';
GRANT ALL PRIVILEGES ON qbox.* TO 'fivem'@'localhost';Not a problem in your case?
Add -- molfar-audit-ignore CFG003 on the reported line (or the line above it), or ignore it in config.json: "ignore": [{ "rule": "CFG003", "resource": "your_resource" }].