In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References
Link Resource
https://github.com/sgranel/directusv8 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-23T18:54:20

Updated: 2024-06-04T17:13:16.123Z

Reserved: 2021-02-23T00:00:00


Link: CVE-2021-27583

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2021-02-23T19:15:14.213

Modified: 2024-06-04T19:17:03.637


Link: CVE-2021-27583

JSON object: View

cve-icon Redhat Information

No data.

CWE