PT-2024-19520 · Seo Panel · Seo Panel
Davide Bernacchia
·
Published
2024-01-30
·
Updated
2024-03-06
·
CVE-2024-22647
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SEO Panel version 4.10.0
Description
A user enumeration issue was found, occurring during user authentication. This issue allows an attacker to determine if a username is valid or not through differences in error messages, enabling a brute-force attack with valid usernames.
Recommendations
For SEO Panel version 4.10.0, consider temporarily restricting access to the user authentication module until a patch is available. As a mitigation measure, avoid using distinct error messages for valid and invalid usernames to prevent user enumeration. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seo Panel