PT-2021-24160 · Cibele · Thinfinity Virtualui

Daniel Morales

·

Published

2021-12-13

·

Updated

2022-07-12

·

CVE-2021-44848

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cibele Thinfinity VirtualUI versions prior to 3.0
Description: The issue concerns the /changePassword endpoint, which returns different responses for invalid authentication requests depending on whether the username exists. This discrepancy can potentially be exploited.
Recommendations: For versions prior to 3.0, consider restricting access to the /changePassword endpoint until a patch is available. As a temporary workaround, avoid using the /changePassword endpoint for authentication requests.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44848

Affected Products

Thinfinity Virtualui