logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-0624

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-0624

Description:
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.
Last updated date:
02/16/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/16/2023
Reference url to background

https://fluidattacks.com/advisories/oberhofer/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy