An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Wed, 09 Jul 2025 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Flytxt
Flytxt neon-dx
CPEs cpe:2.3:a:flytxt:neon-dx:*:*:*:*:*:*:*:*
Vendors & Products Flytxt
Flytxt neon-dx

Tue, 13 May 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-307
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 17:30:00 +0000

Type Values Removed Values Added
Description An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-13T17:25:06.407Z

Reserved: 2023-06-07T00:00:00.000Z

Link: CVE-2023-34732

cve-icon Vulnrichment

Updated: 2025-05-13T17:24:47.133Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-12T18:15:43.840

Modified: 2025-07-09T01:41:24.110

Link: CVE-2023-34732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.