kodbox 1.46.01 has a security flaw that enables user...
Critical severity
Unreviewed
Published
Nov 18, 2023
to the GitHub Advisory Database
•
Updated Nov 25, 2023
Description
Published by the National Vulnerability Database
Nov 18, 2023
Published to the GitHub Advisory Database
Nov 18, 2023
Last updated
Nov 25, 2023
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
References