Brute Force Vulnerability in AniWorld Downloader WebUI Login
CVE-2026-108580
6.9MEDIUM
What is CVE-2026-108580?
AniWorld Downloader versions prior to 5.3.0 exhibit a vulnerability in the WebUI that fails to properly limit authentication attempts. This flaw enables unauthorized attackers to execute brute-force password guessing attacks, allowing them to potentially take over user accounts. By exploiting the timing responses of the verify_user function within the login POST handler, attackers can also enumerate valid usernames. It is crucial for users of AniWorld Downloader to upgrade to version 5.3.0 or later to safeguard their accounts against these risks.
Affected Version(s)
AniWorld Downloader 0 < 5.3.0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SiroxCW
HaiND from the Post and Telecommunication Institute of Technology
