Home
Description
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
References
github.com/...ulnerability-research/tree/main/CVE-2024-55198
cheatsheetseries.owasp.org/...uthentication_Cheat_Sheet.html
github.com/...ulnerability-research/tree/main/CVE-2024-55198