User Enumeration Vulnerability in PHP Jabbers Time Slots Booking Calendar
CVE-2023-33562

9.8CRITICAL

Key Information:

Vendor

PHPjabbers

Vendor
CVE Published:
1 August 2023

What is CVE-2023-33562?

A user enumeration vulnerability exists in PHP Jabbers Time Slots Booking Calendar v3.3, which can be exploited during the password recovery process. This flaw causes the application to return different messages based on whether a username is valid or not. An attacker could utilize this behavior to ascertain valid usernames, thereby facilitating brute force attacks on those accounts.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.