CVE-2024-30176

In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
Configurations

No configuration.

History

29 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) En Logpoint anterior a 7.4.0, un atacante puede enumerar una lista válida de nombres de usuario utilizando URL de widgets compartidos expuestas públicamente.

01 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 18:15

Updated : 2024-10-29 20:35


NVD link : CVE-2024-30176

Mitre link : CVE-2024-30176

CVE.ORG link : CVE-2024-30176


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy