PT-2021-20642 · Unknown · E-Document System
Published
2021-06-16
·
Updated
2021-06-24
·
CVE-2021-34683
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
E-document System version 3.0
Description:
A remote attacker can exploit the issue to obtain the contact information, including names and e-mail addresses, of all users within an organization. This can be achieved through the "kw/auth/bbs/asp/get user email info bbs.asp" API endpoint. The exposed information may facilitate social engineering or brute force attacks against the system's login page.
Recommendations:
For version 3.0, restrict access to the "kw/auth/bbs/asp/get user email info bbs.asp" API endpoint to prevent unauthorized information disclosure. Consider implementing additional security measures to protect against social engineering and brute force attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E-Document System