Vulnerabilities (CVE)

Filtered by vendor Prolion Subscribe
Filtered by product Cryptospike
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36655 1 Prolion 1 Cryptospike 2024-11-21 N/A 9.8 CRITICAL
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.