CVE-2022-40084

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2022
Last modified:
08/05/2025

Description

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opencrx:opencrx:*:*:*:*:*:*:*:* 5.2.2 (including)