Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
One Click Orgs权限许可和访问控制漏洞
Vulnerability Description
One Click Orgs 1.2.3之前版本中存在漏洞。该漏洞源于密码重置失败产生不同的错误信息,该功能取决于电子邮件地址是否已被注册,远程攻击者可借助一系列请求枚举用户账户。
CVSS Information
N/A
Vulnerability Type
N/A