Vulnerability Description
The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Visibility Software | Cyber Recruiter | <= 8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/65564
- http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_detaiVendor Advisory
- http://www.securityfocus.com/bid/65564
- http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_detaiVendor Advisory
FAQ
What is CVE-2014-1931?
CVE-2014-1931 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which mig...
How severe is CVE-2014-1931?
CVE-2014-1931 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1931?
Check the references section above for vendor advisories and patch information. Affected products include: Visibility Software Cyber Recruiter.