Vulnerability Description
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cybelesoft | Thinfinity Virtualui | < 3.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/165327/Cibele-Thinfinity-VirtualUI-2.5.41.0ExploitThird Party AdvisoryVDB Entry
- https://github.com/cybelesoft/virtualui/issues/1Issue TrackingThird Party Advisory
- http://packetstormsecurity.com/files/165327/Cibele-Thinfinity-VirtualUI-2.5.41.0ExploitThird Party AdvisoryVDB Entry
- https://github.com/cybelesoft/virtualui/issues/1Issue TrackingThird Party Advisory
FAQ
What is CVE-2021-44848?
CVE-2021-44848 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
How severe is CVE-2021-44848?
CVE-2021-44848 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44848?
Check the references section above for vendor advisories and patch information. Affected products include: Cybelesoft Thinfinity Virtualui.