Priority - Priority User Enumeration
CVE-2022-23172

5.5MEDIUM

Key Information:

Vendor

Priority

Status
Vendor
CVE Published:
6 July 2022

What is CVE-2022-23172?

An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.

Affected Version(s)

Priority 22.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

: Dudu Moyal - Sophtix Security LTD.
.