HIGH🇵🇱 Wersja polska

CVE-2019-6120

CVSS 7.5v3.1pub. 2019-11-06upd. 2024-11-21

An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email addresses to identify valid ones. By exploiting this vulnerability with CVE-2019-6122 (Username Enumeration) an adversary can enumerate a large number of valid users' Email addresses.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Nicehash Miner

    APP
    Nicehash
    < 2.0.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-6121LOW3.7same product

Odkryto problem w NiceHash Miner przed wersją 2.0.3.0. Brakujące sprawdzenie autoryzacji pozwala atakującemu n...

CVE-2019-6122LOW3.1same product

W NiceHash Miner przed wersją 2.0.3.0 odkryto podatność Username Enumeration via Error Message. System wyświet...

CVE-2025-56513CRITICAL9.8PL ✓same vendor

RCE przez niezabezpieczony mechanizm aktualizacji w NiceHash QuickMiner