Arbitrary User Account Exposure in OrangeScrum by OrangeScrum
CVE-2023-0624

6.1MEDIUM

Key Information:

Vendor
CVE Published:
9 February 2023

What is CVE-2023-0624?

A security flaw in OrangeScrum version 2.0.11 enables an external attacker to access arbitrary user accounts. This vulnerability arises from the application's handling of malicious user input, which can lead to sensitive user data being disclosed in the application's response, with an incorrect content-type of text/html. This poses a significant risk to user privacy and data integrity within the application.

Affected Version(s)

OrangeScrum 2.0.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-0624 : Arbitrary User Account Exposure in OrangeScrum by OrangeScrum