PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://github.com/pwndoc/pwndoc/issues/381 | issue tracking exploit third party advisory |
https://cve.nstsec.com/cve-2022-44022 |