Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrqw-j89v-qc52

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.

EPSS

Процентиль: 68%
0.00575
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.

EPSS

Процентиль: 68%
0.00575
Низкий