Back

CRITICAL

User Enumeration vulnerability

Published Oct 4, 2024

Description

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.

Affected products

Remediation

Vendor solution

Upgrade Client Dashboard to version 9.7.0

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CERT-In
Published Oct 4, 2024
Updated Oct 4, 2024
Reserved Sep 30, 2024

CISA Vulnrichment

Updated Oct 4, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner CERT-In
Published Oct 4, 2024
Updated Oct 4, 2024

GitHub

No data