Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38c2-vx55-m3wp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

EPSS

Процентиль: 71%
0.01467
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
почти 6 лет назад

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

EPSS

Процентиль: 71%
0.01467
Низкий