Email Enumeration Vulnerability in NiceHash Miner by NiceHash
CVE-2019-6120
7.5HIGH
What is CVE-2019-6120?
A vulnerability in earlier versions of NiceHash Miner allows attackers to exploit a lack of rate limiting when adding wallet addresses via email. Attackers can submit numerous email addresses to identify valid ones. When combined with another vulnerability that supports username enumeration, an adversary can effectively compile a list of valid user email addresses, posing significant privacy risks to users and leading to potential phishing attacks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
