Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-10848. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates username enumeration in CBAS-Web 19.0.0 by analyzing the difference in error messages returned for valid vs. invalid usernames during login attempts. The PoC shows how an attacker can distinguish between valid and invalid usernames based on the response content.
Description
Computrols CBAS 18.0.0 allows Username Enumeration.
Exploits (1)
This exploit demonstrates username enumeration in CBAS-Web 19.0.0 by analyzing the difference in error messages returned for valid vs. invalid usernames during login attempts. The PoC shows how an attacker can distinguish between valid and invalid usernames based on the response content.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N