PT-2024-19520 · Seo Panel · Seo Panel

Davide Bernacchia

·

Published

2024-01-30

·

Updated

2024-03-06

·

CVE-2024-22647

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SEO Panel version 4.10.0
Description A user enumeration issue was found, occurring during user authentication. This issue allows an attacker to determine if a username is valid or not through differences in error messages, enabling a brute-force attack with valid usernames.
Recommendations For SEO Panel version 4.10.0, consider temporarily restricting access to the user authentication module until a patch is available. As a mitigation measure, avoid using distinct error messages for valid and invalid usernames to prevent user enumeration. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Weakness Enumeration

Related Identifiers

BIT-SEOPANEL-2024-22647
CVE-2024-22647

Affected Products

Seo Panel