NA

CVE-2022-44005

Published: 16/11/2022 Updated: 21/11/2022
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

backclick backclick 5.9.63