CVE-2023-30458
MEDIUMMedicine Tracker System 1.0 - Username Enumeration via Login Response Time Discrepancy
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-30458. PoCs published by d34dun1c02n.
AI-analyzed exploit summary This repository contains a detailed writeup describing a username enumeration vulnerability (CVE-2023-30458) in Medicine Tracker System 1.0, leveraging response timing discrepancies to identify valid usernames. The attack involves using Burp Suite to analyze response times for valid vs. invalid usernames.
Description
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.
Exploits (1)
This repository contains a detailed writeup describing a username enumeration vulnerability (CVE-2023-30458) in Medicine Tracker System 1.0, leveraging response timing discrepancies to identify valid usernames. The attack involves using Burp Suite to analyze response times for valid vs. invalid usernames.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N