CVE-2024-24720

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 - () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 -
References () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate - () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate -

14 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-200

02 May 2024, 17:15

Type Values Removed Values Added
Summary (en) An issue was discovered on Innovaphone PBX before 14r1 devices. It provides different responses to incoming requests in a way that reveals information to an attacker. (en) An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
References
  • () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate -

27 Feb 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 01:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24720

Mitre link : CVE-2024-24720

CVE.ORG link : CVE-2024-24720


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor