User Enumeration vulnerability
Published Oct 4, 2024
9.3
CRITICALCVSS 4.0
EPSS 0.51%
Description
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.
Affected products
-
Affected
- < 9.7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Shilpi Computers | Client Dashboard | unaffected | Affected
|
- < 9.7.0
-
Affected
- ≥ 0, < 9.7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Shilpisoft | Client Dashboard | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade Client Dashboard to version 9.7.0
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-42581 Advisory
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-42581 | Advisory | |
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data