CVE-2024-47656

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
04/10/2024
Last modified:
16/10/2024

Description

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:* 9.7.0 (excluding)