PT-2023-12997 · Entab Erp · Entab Erp

CVE-2022-30076

·

Publicado

2023-04-16

·

Atualizado

2025-02-06

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ENTAB ERP version 1.0
Description The issue allows attackers to discover users' full names via a brute force attack by trying a series of student usernames, such as s10000 through s20000, due to the lack of rate limiting.
Recommendations For ENTAB ERP version 1.0, consider implementing rate limiting on login attempts to prevent brute force attacks. As a temporary workaround, restrict access to the student username series to minimize the risk of exploitation. Avoid using sequential student usernames until the issue is resolved.

Exploit

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-30076

Produtos afetados

Entab Erp