漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenProject is vulnerable to user enumeration via the change password function
Vulnerability Description
OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST request to the /account/change_password endpoint with an arbitrary User ID as the password_change_user_id parameter, the resulting error page would show the username for the requested user. Since this endpoint is intended to be called without being authenticated, this allows to enumerate the user names of all accounts registered in an OpenProject instance. This issue has been patched in version 16.6.2.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
OpenProject 信息泄露漏洞
Vulnerability Description
OpenProject是OpenProject开源的一个基于Web的项目管理软件。 OpenProject 11.2.1版本至16.6.2之前版本存在信息泄露漏洞,该漏洞源于错误页面泄露用户名信息,可能导致账户枚举。
CVSS Information
N/A
Vulnerability Type
N/A