PT-2023-12997 · Entab Erp · Entab Erp
Published
2023-04-16
·
Updated
2025-02-06
·
CVE-2022-30076
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ENTAB ERP version 1.0
Description
The issue allows attackers to discover users' full names via a brute force attack by trying a series of student usernames, such as s10000 through s20000, due to the lack of rate limiting.
Recommendations
For ENTAB ERP version 1.0, consider implementing rate limiting on login attempts to prevent brute force attacks.
As a temporary workaround, restrict access to the student username series to minimize the risk of exploitation.
Avoid using sequential student usernames until the issue is resolved.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Entab Erp