CVE-2024-47656
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.
CRITICAL · CVSS 9.8
EPSS 0.00779
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0