Vulnerability Description
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ordat | Ordat.Erp | < 2.24.01 |
Related Weaknesses (CWE)
References
- http://foss-online.comBroken Link
- http://ordat.comProduct
- https://mind-bytes.de/offenlegung-existierender-benutzerkonten-in-foss-online-cvExploitTechnical Description
FAQ
What is CVE-2024-34336?
CVE-2024-34336 is a vulnerability with a CVSS score of 5.3 (MEDIUM). User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password funct...
How severe is CVE-2024-34336?
CVE-2024-34336 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-34336?
Check the references section above for vendor advisories and patch information. Affected products include: Ordat Ordat.Erp.