9.8
CVE-2023-48028
- EPSS 1.11%
- Veröffentlicht 18.11.2023 00:15:07
- Zuletzt bearbeitet 29.09.2025 14:16:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.11% | 0.616 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deae
https://nitipoom-jar.github.io/CVE-2023-48028/
https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2023-48028