Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 27 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects unknown code of the file /account/_settings of the component Email Change Handler. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | VirtFusion Email Change _settings excessive authentication | |
| Weaknesses | CWE-307 CWE-799 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-27T20:27:37.336Z
Reserved: 2025-10-26T17:15:36.557Z
Link: CVE-2025-12310
Updated: 2025-10-27T20:27:31.977Z
Status : Received
Published: 2025-10-27T20:15:51.943
Modified: 2025-10-27T20:15:51.943
Link: CVE-2025-12310
No data.
OpenCVE Enrichment
No data.