CVE-2014-1931

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:visibility_software:cyber_recruiter:*:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.2:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.4:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.6:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.8:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.0:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-02-10 22:55

Updated : 2024-02-04 18:35


NVD link : CVE-2014-1931

Mitre link : CVE-2014-1931

CVE.ORG link : CVE-2014-1931


JSON object : View

Products Affected

visibility_software

  • cyber_recruiter
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor