← volver
CVE-2022-40292mediumCWE-209

Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.3epss 0.5%
probabilidad de explotación
0.5%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N