Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-1931

Опубликовано: 10 фев. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:visibility_software:cyber_recruiter:*:*:*:*:*:*:*:*
Версия до 8.0 (включая)
cpe:2.3:a:visibility_software:cyber_recruiter:6.2:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.4:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.6:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.8:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.0:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.2:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.0025
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

EPSS

Процентиль: 48%
0.0025
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200