CVE-2021-44155

CVE-2021-44155

An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

Source: CVE-2021-44155

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다