First published: Mon Aug 28 2023(Updated: )
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpjabbers Restaurant Booking Script | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the User enumeration vulnerability in PHP Jabbers Restaurant Booking Script v3.0 is CVE-2023-40759.
The severity rating of CVE-2023-40759 is critical with a value of 9.8.
The User enumeration vulnerability in PHP Jabbers Restaurant Booking Script v3.0 occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not.
An attacker can use the User enumeration vulnerability in PHP Jabbers Restaurant Booking Script v3.0 to perform a brute force attack with valid users.
It is recommended to update to a patched version provided by PHP Jabbers to fix the User enumeration vulnerability in PHP Jabbers Restaurant Booking Script v3.0.