First published: Wed Aug 26 2020(Updated: )
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Human Resource Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24008 is classified as a medium severity vulnerability due to its potential to allow user enumeration and facilitate brute force attacks.
To fix CVE-2020-24008, implement consistent password recovery messages regardless of the user's validity to prevent enumeration.
CVE-2020-24008 is a user enumeration vulnerability in the password recovery process.
CVE-2020-24008 affects Umanni Human Resources version 1.0.
An attacker can use CVE-2020-24008 to determine valid usernames through distinct messages in the password recovery process.