CVE-2021-34683 details a vulnerability in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0, allowing remote attackers to extract the names and email addresses of all organizational users via the kw/auth/bbs/asp/get_user_email_info_bbs.asp endpoint. This information disclosure, rated Medium severity (CVSS 5.3), could facilitate social engineering or brute-force attacks against the system's login page. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:eic:e-document_system:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.