Описание
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| snipe-it | itp | package |
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
CVSS3: 5.3
github
около 3 лет назад
Snipe-IT allows attackers to check whether a user account exists