Vulnerabilities > CVE-2023-36127 - Information Exposure Through Discrepancy vulnerability in PHPjabbers Appointment Scheduler 3.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
phpjabbers
CWE-203

Summary

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

Vulnerable Configurations

Part Description Count
Application
Phpjabbers
1

Common Weakness Enumeration (CWE)