PT-2024-28392 · Kaiten · Kaiten
Artemy-Ccrsky
·
Published
2024-07-04
·
Updated
2024-08-22
·
CVE-2024-39211
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kaiten version 57.128.8
Description
The issue allows remote attackers to enumerate user accounts via a crafted POST request. This is possible because a login response contains a
user email field only if the user account exists.Recommendations
For Kaiten version 57.128.8, consider modifying the login response to not include the
user email field, or implement additional checks to prevent user account enumeration. As a temporary workaround, restrict access to the login endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaiten