Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv5r-jf97-8xjm

Опубликовано: 11 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

EPSS

Процентиль: 63%
0.00452
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

EPSS

Процентиль: 63%
0.00452
Низкий

Дефекты

CWE-200