CVE-2022-30076
MEDIUMENTAB ERP 1.0 - Information Disclosure via Brute Force Attack
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-30076. PoCs published by Deb Prasad Banerjee.
AI-analyzed exploit summary This exploit describes a broken access control vulnerability in ENTAB ERP 1.0, allowing an attacker to enumerate usernames and full names via brute-force attacks on the UserId parameter without rate limiting. The PoC involves intercepting requests and using Burp Suite Intruder to automate the attack.
Description
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.
Exploits (1)
This exploit describes a broken access control vulnerability in ENTAB ERP 1.0, allowing an attacker to enumerate usernames and full names via brute-force attacks on the UserId parameter without rate limiting. The PoC involves intercepting requests and using Burp Suite Intruder to automate the attack.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N