CVE-2024-47059
CVE-2024-47059
Título es
CVE-2024-47059
Mié, 18/09/2024 – 22:15
Tipo
CWE-200
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-47059
Descripción en
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak.
However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification.
This difference could be used to perform username enumeration.
19/09/2024
19/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
0.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
NONE
Enviar en el boletín
Off
