This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 04 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Shilpisoft
Shilpisoft client Dashboard |
|
CPEs | cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:* | |
Vendors & Products |
Shilpisoft
Shilpisoft client Dashboard |
|
Metrics |
ssvc
|
Fri, 04 Oct 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts. | |
Title | User Enumeration vulnerability | |
Weaknesses | CWE-307 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-In
Published: 2024-10-04T12:24:27.872Z
Updated: 2024-10-04T13:38:38.800Z
Reserved: 2024-09-30T11:42:54.095Z
Link: CVE-2024-47656
Vulnrichment
Updated: 2024-10-04T13:38:32.493Z
NVD
Status : Analyzed
Published: 2024-10-04T13:15:11.910
Modified: 2024-10-16T15:32:01.460
Link: CVE-2024-47656
Redhat
No data.