← Back

CVE-2018-15656

nvd nist
Published: Feb 5, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base64 encoded e-mail address, to receive confirmation as to whether a user account exists in the system with the specified e-mail address. The request must be made with an "apiKey" value in the "ApiKey" header.

Affected (1)

Products: 42gears: Suremdm
1 product
Suremdm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2018-11-27

Timeline

No history available yet.