User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
References
Link | Resource |
---|---|
https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html | Technical Description |
https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 | Exploit Third Party Advisory |
https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 | Exploit Third Party Advisory |
Configurations
History
03 Apr 2025, 18:31
Type | Values Removed | Values Added |
---|---|---|
References | () https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html - Technical Description | |
References | () https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 - Exploit, Third Party Advisory | |
First Time |
Celk
Celk celk Saude |
|
CPE | cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:* |
19 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CWE | CWE-204 | |
Summary |
|
|
References | () https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 - |
13 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-13 15:15
Updated : 2025-04-03 18:31
NVD link : CVE-2024-55198
Mitre link : CVE-2024-55198
CVE.ORG link : CVE-2024-55198
JSON object : View
Products Affected
celk
- celk_saude
CWE
CWE-204
Observable Response Discrepancy