In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/en/advisories/VDE-2021-037/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2021-10-27T10:25:09.307226Z
Updated: 2024-09-17T01:41:24.149Z
Reserved: 2021-06-10T00:00:00
Link: CVE-2021-34580
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-27T11:15:07.553
Modified: 2024-11-21T06:10:44.700
Link: CVE-2021-34580
Redhat
No data.