5.3
CVE-2019-16180
- EPSS 1.7%
- Veröffentlicht 09.09.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:13
- Erkennungen
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Limesurvey ≫ Limesurvey Version < 3.17.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.7% | 0.742 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released
https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R44