Home

Description

User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.

PUBLISHED Reserved 2024-12-06 | Published 2025-03-13 | Updated 2025-03-19 | Assigner mitre

References

github.com/...ulnerability-research/tree/main/CVE-2024-55198 exploit

cheatsheetseries.owasp.org/...uthentication_Cheat_Sheet.html

github.com/...ulnerability-research/tree/main/CVE-2024-55198

cve.org (CVE-2024-55198)

nvd.nist.gov (CVE-2024-55198)

Download JSON