Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7h3-m79w-rcrp

Опубликовано: 16 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

EPSS

Процентиль: 85%
0.0248
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

EPSS

Процентиль: 85%
0.0248
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307