PT-2023-23662 · Roundcube · Roundcube Password Recovery Plugin
Pedro José Navas Pérez
·
Publicado
2023-09-04
·
Atualizado
2023-09-08
·
CVE-2023-3221
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube Password Recovery plugin version 1.2
Description
The issue allows a remote attacker to create a test script against the password recovery function to enumerate all users in the database. This is a user enumeration vulnerability in the Password Recovery plugin for Roundcube.
Recommendations
For Roundcube Password Recovery plugin version 1.2, consider disabling the password recovery function until a patch is available to prevent user enumeration. Restrict access to the password recovery module to minimize the risk of exploitation. Avoid using the password recovery feature in the affected plugin until the issue is resolved.
Correção
Side Channel Attack
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Roundcube Password Recovery Plugin