CVE-2024-2463

HIGH

CDeX <5.7.1 - Info Disclosure

Title source: llm

Description

Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.

Scores

CVSS v3 8.0
EPSS 0.0021
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-640
Status published

Affected Products (1)

cdex/cdex < 5.71

Timeline

Published Mar 21, 2024
Tracked Since Feb 18, 2026