CVE-2024-33856 Information

Description

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.

Reference

https://servicedesk.logpoint.com/hc/en-us/categories/200832975-Knowledge-Center https://servicedesk.logpoint.com/hc/en-us/articles/18533583876253-Username-enumeration-using-the-forget-password-endpoint

Share on: