First published: Thu Oct 20 2022(Updated: )
OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opencrx Opencrx | <=5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40084 is a vulnerability in OpenCRX software that allows an attacker to determine if a username, email, or ID is valid through password enumeration.
The severity of CVE-2022-40084 is medium with a CVSS score of 5.3.
CVE-2022-40084 works by exploiting the differences in error messages received during a password reset process to determine the validity of a username, email, or ID.
OpenCRX versions up to and including v5.2.2 are affected by CVE-2022-40084.
To fix CVE-2022-40084, users should update their OpenCRX software to version 5.2.2 or higher.