User enumeration vulnerability in ORDAT FOSS-Online...
Moderate severity
Unreviewed
Published
Sep 12, 2024
to the GitHub Advisory Database
•
Updated Sep 18, 2024
Description
Published by the National Vulnerability Database
Sep 12, 2024
Published to the GitHub Advisory Database
Sep 12, 2024
Last updated
Sep 18, 2024
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.
References