Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Community Registered Email Exposure Vulnerability

$
0
0

Publish Date: Oct. 23, 2018

Summary

We've identified and fixed a vulnerability in the Spiceworks Community that could allow an attacker to determine if a Spiceworks Community account exists for a specific email address.

Who’s Affected?

At this time we do not believe anyone was affected by this vulnerability.

Details

When re-sending email verification emails through the Spiceworks Community, the system would have multiple messages depending on whether the email address has been registered but not verified, verified, or not registered. An attacker could use these responses to determine if an email address has a Spiceworks Community profile associated with it. This could allow for a targeted attack on a Community profile.

Mitigating Factors

To exploit this vulnerability, the attacker would have to know the email address to check and would...


Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>