Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85hh-xxh7-6rvg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

EPSS

Процентиль: 58%
0.00358
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

EPSS

Процентиль: 58%
0.00358
Низкий

Дефекты

CWE-200