User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
References
| Link | Resource |
|---|---|
| https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html | Technical Description |
| https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 | Exploit Third Party Advisory |
| https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-03-13 15:15
Updated : 2025-04-03 18:31
NVD link : CVE-2024-55198
Mitre link : CVE-2024-55198
CVE.ORG link : CVE-2024-55198
JSON object : View
Products Affected
celk
- celk_saude
CWE
CWE-204
Observable Response Discrepancy
