CVE-2020-35398

MEDIUM

UTI Mutual Fund Invest Online < 5.4.28 - Username Enumeration via Error Message

Title source: llm
STIX 2.1

Description

An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0112
EPSS Percentile 61.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (1)
utimf/uti_mutual_fund_invest_online < 5.4.28
Published Dec 23, 2021
Tracked Since Feb 18, 2026