VulnerabilityModified
CVE-2023-48028
This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
CRITICAL 9.8EPSS 1.11%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-307
- Affected
- kodcloud/kodbox
- Source
- cve@mitre.org
References
- https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deaeBroken Link
- https://nitipoom-jar.github.io/CVE-2023-48028/Exploit
- https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2023-48028
- https://gist.github.com/bugplorer/9ae8ad7a9f2a3053ebd07a1b7b54deaeBroken Link
- https://nitipoom-jar.github.io/CVE-2023-48028/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.