Vulnerability CVE-2024-1145


Published: 2024-03-19

Description:
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.

Type:

CWE-204

(Response Discrepancy Information Exposure)

 References:
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-alma-devklan-blog

Copyright 2024, cxsecurity.com

 

Back to Top