CVE-2023-48028

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kodcloud:kodbox:1.46.01:*:*:*:*:*:*:*

History

25 Nov 2023, 02:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:kodcloud:kodbox:1.46.01:*:*:*:*:*:*:*
First Time Kodcloud
Kodcloud kodbox
CWE CWE-307
References () https://nitipoom-jar.github.io/CVE-2023-48028/ - () https://nitipoom-jar.github.io/CVE-2023-48028/ - Exploit
References () https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deae - () https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deae - Broken Link

18 Nov 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-18 00:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-48028

Mitre link : CVE-2023-48028

CVE.ORG link : CVE-2023-48028


JSON object : View

Products Affected

kodcloud

  • kodbox
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts