Username Enumeration Vulnerability in NiceHash Miner by NiceHash
CVE-2019-6122
3.1LOW
What is CVE-2019-6122?
A vulnerability exists in NiceHash Miner versions prior to 2.0.3.0 that allows attackers to exploit an error message to determine if a submitted email address is associated with an account. The application delivers an 'EMAIL DOES NOT EXIST' response for incorrect entries, while valid email addresses receive a different error message in the event of invalid credentials. This discrepancy can enable unauthorized users to confirm the existence of an account based on the error responses, potentially leading to targeted attacks.
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
