molfar_audit / Rules / CFG003

CFG003 Database user is root or has no password

critical Server config

mysql_connection_string uses the root user or an empty password.

Why it matters

Any SQL injection in any resource then gets full control of every database on the host. A passwordless database is one firewall mistake away from being public. The report never shows the connection string itself.

How to fix

Create a dedicated database user with rights only on the server database and a strong password.

Fixed
CREATE USER 'fivem'@'localhost' IDENTIFIED BY 'long-random-password';
GRANT ALL PRIVILEGES ON qbox.* TO 'fivem'@'localhost';

Not a problem in your case?

Add -- molfar-audit-ignore CFG003 on the reported line (or the line above it), or ignore it in config.json: "ignore": [{ "rule": "CFG003", "resource": "your_resource" }].