Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/95737 | third party advisory vdb entry |
http://www.securityfocus.com/archive/1/533345/100/0/threaded | mailing list third party advisory vdb entry |
http://packetstormsecurity.com/files/128157/ProjectDox-8.1-XSS-User-Enumeration-Ciphertext-Reuse.html | third party advisory vdb entry |