PT-2025-9507 · Pypi · Flask-Appbuilder

·

CVE-2025-24023

·

Published

2025-03-03

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flask-AppBuilder versions prior to 4.5.3
Description The issue allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.
Recommendations For versions prior to 4.5.3, update to version 4.5.3 to resolve the issue.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN24336
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2025-24023
ECHO-04FF-1109-61D3
GHSA-P8Q5-CVWX-WVWP
PYSEC-2025-15

Affected Products

Flask-Appbuilder