PT-2024-25794 · Unknown · Ordat Foss-Online

Simon Holl

·

Published

2024-09-12

·

Updated

2024-09-18

·

CVE-2024-34336

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ORDAT FOSS-Online versions prior to 2.24.01
Description A user enumeration issue exists, allowing attackers to determine if an account exists in the application by comparing server responses of the forgot password functionality.
Recommendations For versions prior to 2.24.01, update to version 2.24.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the forgot password functionality until a patch is available.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-34336

Affected Products

Ordat Foss-Online