PT-2022-27084 · Pwndoc · Pwndoc

Astarufo

·

Published

2022-10-29

·

Updated

2024-05-02

·

CVE-2022-44022

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PwnDoc versions 0.5.3 and earlier
Description The issue allows remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
Recommendations For PwnDoc versions 0.5.3 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2022-44022

Affected Products

Pwndoc