Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
References
Link | Resource |
---|---|
http://www.sk-it.com/en/cve.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-05-13 12:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-7217
Mitre link : CVE-2019-7217
JSON object : View
CWE
CWE-203
Observable Discrepancy
Products Affected
citrix
- sharefile