CVE-2020-15392
A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
- Affected products
- Venki Supravizio Bpm
- Venki Supravizio Bpm
- = 10.1.2
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-203
- NVD status
- Modified
- Published
- 2020-07-07
CVE-2020-15392 at NVD
1 known exploit for CVE-2020-15392
Proof-of-concept code and exploit modules indexed by Sploitus