CVE-2020-35398
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
Affected (1)
Products: Utimf: Uti Mutual Fund Invest Online
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.4.28 |
References (4)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Timeline
No history available yet.