5.3
CVSSv3

CVE-2021-44848

Published: 13/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Cibele Thinfinity VirtualUI prior to 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cybelesoft thinfinity virtualui

Exploits

Cibele Thinfinity VirtualUI version 25410 suffers from a user enumeration vulnerability ...

Github Repositories

nuclei_templates

Nuclei Template I have finally decided to contribute to the IT Security field, and what a better way to do it than starting by creating templates for Nuclei (nucleiprojectdiscoveryio) Templates CVE-2021-44848: Thinfinity VirtualUI is a web remote desktop system, a vulnerability exist in the parameter "username" located in /changePassword that allows user enumerati