PT-2023-26052 · Unknown · Uvdesk Community Skeleton

CVE-2023-37635

·

Publicado

2023-10-23

·

Atualizado

2023-10-30

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UVDesk Community Skeleton version 1.1.1
Description The issue allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. This can be done through the login page, allowing attackers to potentially gain unauthorized access.
Recommendations For UVDesk Community Skeleton version 1.1.1, consider implementing rate limiting or IP blocking on the login page to prevent brute force attacks until a patch is available. As a temporary workaround, restrict access to the login page to minimize the risk of exploitation.

Exploit

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37635

Produtos afetados

Uvdesk Community Skeleton