Описание
Snipe-IT allows attackers to check whether a user account exists
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
Пакеты
Наименование
snipe/snipe-it
composer
Затронутые версииВерсия исправления
<= 6.0.14
Отсутствует
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
CVSS3: 5.3
debian
около 3 лет назад
Snipe-IT through 6.0.14 allows attackers to check whether a user accou ...