Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7jww-fm5p-pj92

Опубликовано: 17 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

EPSS

Процентиль: 42%
0.00202
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

EPSS

Процентиль: 42%
0.00202
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639