CVE-2020-24008: Medium severity human resource management system vulnerability
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24008?
CVE-2020-24008 is classified as a medium severity vulnerability due to its potential to allow user enumeration and facilitate brute force attacks.
How do I fix CVE-2020-24008?
To fix CVE-2020-24008, implement consistent password recovery messages regardless of the user's validity to prevent enumeration.
What type of vulnerability is CVE-2020-24008?
CVE-2020-24008 is a user enumeration vulnerability in the password recovery process.
What software versions are affected by CVE-2020-24008?
CVE-2020-24008 affects Umanni Human Resources version 1.0.
What can an attacker do with CVE-2020-24008?
An attacker can use CVE-2020-24008 to determine valid usernames through distinct messages in the password recovery process.