CVE-2023-48028
PoC —CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- Vendors
- kodcloud
- Products
- kodbox
- Weakness
- CWE-307
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.