CVE-2020-24007: Critical severity human resource management system vulnerability
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-24007?
CVE-2020-24007 is a security flaw in Umanni RH 1.0 that allows an unauthenticated user to perform brute-force attacks on the Login page due to unlimited authentication attempts.
What are the consequences of CVE-2020-24007?
Exploitation of CVE-2020-24007 may allow attackers to gain unauthorized access to user accounts through brute-force login attempts.
How do I fix CVE-2020-24007?
To mitigate CVE-2020-24007, implement account lockout mechanisms or limit the number of authentication attempts within Umanni RH 1.0.
Which versions of Umanni RH are affected by CVE-2020-24007?
CVE-2020-24007 affects Umanni RH version 1.0 specifically.
Who can exploit CVE-2020-24007?
CVE-2020-24007 can be exploited by any unauthenticated user attempting to access the Login page of Umanni RH 1.0.