← volver
CVE-2024-0491

Huaxia ERP UserController.java password recovery

CVSS 5.3 MEDIUMEPSS 0.6%CWE-640
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 ene 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250596.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Productos afectados
Huaxia · ERP

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →