CVE-2024-24720
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
27/02/2024
Last modified:
30/05/2025
Description
An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24720
- https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720
- https://wiki.innovaphone.com/index.php?title=Reference14r1%3ARelease_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate
- https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720
- https://wiki.innovaphone.com/index.php?title=Reference14r1%3ARelease_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate