CVE-2024-2463

HIGH

CDeX <5.7.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.

Scores

CVSS v3 8.0
EPSS 0.0021
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-640
Status published
Products (1)
cdex/cdex < 5.71
Published Mar 21, 2024
Tracked Since Feb 18, 2026