PT-2019-17965 · Nicehash · Nicehash Miner

Ashutosh Barot

·

Published

2019-11-06

·

Updated

2020-08-24

·

CVE-2019-6122

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NiceHash Miner versions prior to 2.0.3.0
Description A Username Enumeration via Error Message issue was discovered because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.
Recommendations For versions prior to 2.0.3.0, update to version 2.0.3.0 or later to resolve the issue.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6122

Affected Products

Nicehash Miner