PT-2025-9507 · Pypi · Flask-Appbuilder

Millad7

·

Published

2025-03-03

·

Updated

2025-03-04

·

CVE-2025-24023

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flask-AppBuilder versions prior to 4.5.3
Description The issue allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.
Recommendations For versions prior to 4.5.3, update to version 4.5.3 to resolve the issue.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24023
GHSA-P8Q5-CVWX-WVWP
PYSEC-2025-15

Affected Products

Flask-Appbuilder