CVE-2014-1931

The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:visibility_software:cyber_recruiter:*:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.2:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.4:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.6:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:6.8:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.0:*:*:*:*:*:*:*
cpe:2.3:a:visibility_software:cyber_recruiter:7.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/65564 - () http://www.securityfocus.com/bid/65564 -
References () http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_details - Vendor Advisory () http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_details - Vendor Advisory

Information

Published : 2014-02-10 22:55

Updated : 2024-11-21 02:05


NVD link : CVE-2014-1931

Mitre link : CVE-2014-1931

CVE.ORG link : CVE-2014-1931


JSON object : View

Products Affected

visibility_software

  • cyber_recruiter
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor