Description
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.
Remediation
References
Related Vulnerabilities
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2024-38023)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8005)
Joomla! Core 1.5.x Cross-Site Scripting (1.5.0 - 1.5.11)
Oracle Application Server CVE-2008-5438 Vulnerability (CVE-2008-5438)