Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37641
HistoryOct 21, 2022 - 12:07 p.m.

Information Disclosure

2022-10-2112:07:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
opencrx-core
information disclosure
remote attacker
password enumeration

0.001 Low

EPSS

Percentile

37.0%

org.opencrx:opencrx-core is vulnerable to information disclosure. A remote attacker is able to determine if a username, email or an ID is valid through password enumeration due to the difference in error messages received during a password reset.

0.001 Low

EPSS

Percentile

37.0%

Related for VERACODE:37641