5.3
CVSSv3

CVE-2022-30076

Published: 16/04/2023 Updated: 26/04/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

ENTAB ERP 1.0 allows malicious users to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

entab erp 1.0

Exploits

ENTAB ERP version 10 suffers from a username information leak due to a lack of rate limiting ...