Vulnerabilities > CVE-2020-26526 - Unspecified vulnerability in Damstratechnology Smart Asset 2020.7

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
damstratechnology

Summary

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

Vulnerable Configurations

Part Description Count
Application
Damstratechnology
1