CVE-2019-11233 is a high-severity information disclosure vulnerability affecting EXCELLENT INFOTEK BiYan versions 1.57 through 2.8. An unauthenticated attacker can leak sensitive user information, such as email addresses or telephone numbers, by sending a crafted request to the 'check_user_login_info.aspx' URI. This vulnerability has a CVSS score of 7.5, indicating a high impact on confidentiality with no authentication or user interaction required. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using affected BiYan versions should be aware of this potential data leak risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.57, <= 2.8CPE matchmatch criteria | cpe:2.3:a:eic:biyan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.