VYPR
High severity7.5NVD Advisory· Published Nov 6, 2019· Updated Jun 17, 2026

CVE-2019-6120

CVE-2019-6120

Description

An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email addresses to identify valid ones. By exploiting this vulnerability with CVE-2019-6122 (Username Enumeration) an adversary can enumerate a large number of valid users' Email addresses.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nicehash/Miner2 versions
    cpe:2.3:a:nicehash:miner:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nicehash:miner:*:*:*:*:*:*:*:*range: <2.0.3.0
    • (no CPE)range: <2.0.3.0
  • NiceHash Miner/NiceHash Minerdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.