PT-2024-40294 · Packagist · Silverstripe/Framework
Published
2024-05-27
·
Updated
2024-05-27
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
No specific software or versions mentioned, so:
Software (affected versions not specified)
Description:
The issue concerns a user ID enumeration vulnerability in brute force error messages. It allows an attacker to infer or confirm user details that exist in the member table by exploiting the difference in login attempt logging and lockout processes for non-existent and existent users. This vulnerability has been resolved by ensuring that the login attempt logging and lockout process works equivalently for both non-existent and existent users.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverstripe/Framework