ZeroHour

CVE-2023-48028

PoC
CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

Vendors
kodcloud
Products
kodbox
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.