CVE-2024-54454
CVE-2024-54454
Título es
CVE-2024-54454
Vie, 27/12/2024 – 20:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-54454
Descripción en
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.
27/12/2024
27/12/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off