Vulnerabilities > CVE-2020-24008 - Information Exposure Through Discrepancy vulnerability in Umanni Human Resources 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |