Описание
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:entab:erp:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.0248
Низкий
5.3 Medium
CVSS3
Дефекты
NVD-CWE-Other
CWE-307
Связанные уязвимости
CVSS3: 5.3
github
почти 3 года назад
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.
EPSS
Процентиль: 85%
0.0248
Низкий
5.3 Medium
CVSS3
Дефекты
NVD-CWE-Other
CWE-307