Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq45-vc8j-2q5c

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 12 лет назад

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-200