9.8

CVE-2023-48028

Exploit
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KodcloudKodbox Version1.46.01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.616
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deae
Broken Link
https://nitipoom-jar.github.io/CVE-2023-48028/
Exploit
https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2023-48028