Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2fj-pxhr-mx98

Опубликовано: 18 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

EPSS

Процентиль: 55%
0.00329
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

EPSS

Процентиль: 55%
0.00329
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307