Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://github.com/ifmacedo/mconnect/blob/main/bruteforce | third party advisory |
https://www.linkedin.com/pulse/descobrindo-usu%C3%A1rios-brute-force-iran/ | third party advisory exploit |