5
CVSSv2

CVE-2011-4678

Published: 06/12/2011 Updated: 08/12/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The password reset feature in One Click Orgs prior to 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote malicious users to enumerate user accounts via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

oneclickorgs one click orgs 1.0.0

oneclickorgs one click orgs 1.0.1

oneclickorgs one click orgs 1.2.0

oneclickorgs one click orgs 1.1.0

oneclickorgs one click orgs

oneclickorgs one click orgs 1.2.1

oneclickorgs one click orgs 1.1.1