Description
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.
Remediation
References
Related Vulnerabilities
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-1648)
WordPress Plugin EMC2 Custom Help Videos Cross-Site Scripting (1.2)
Phusion Passenger Other Vulnerability (CVE-2014-1832)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3946)
WordPress Missing Authentication for Critical Function Vulnerability (CVE-2020-11028)