Information Leakage in Mobicint Backend for Credit Unions v3

Information Leakage in Mobicint Backend for Credit Unions v3

CVE-2021-36436 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint.

Learn more about our User Device Pen Test.