Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-3605", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2023-07-10T19:20:05.031Z", "datePublished": "2023-07-10T20:00:04.915Z", "dateUpdated": "2024-10-15T18:33:35.103Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2023-10-23T14:49:19.445Z"}, "title": "PHPGurukul Online Shopping Portal Registration Page excessive authentication", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-307", "lang": "en", "description": "CWE-307 Improper Restriction of Excessive Authentication Attempts"}]}], "affected": [{"vendor": "PHPGurukul", "product": "Online Shopping Portal", "versions": [{"version": "1.0", "status": "affected"}], "modules": ["Registration Page"]}], "descriptions": [{"lang": "en", "value": "A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233467."}, {"lang": "de", "value": "In PHPGurukul Online Shopping Portal 1.0 wurde eine kritische Schwachstelle ausgemacht. Betroffen ist eine unbekannte Verarbeitung der Komponente Registration Page. Durch die Manipulation mit unbekannten Daten kann eine improper restriction of excessive authentication attempts-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren."}], "metrics": [{"cvssV3_1": {"version": "3.1", "baseScore": 6.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "baseSeverity": "MEDIUM"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 6.5, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "baseSeverity": "MEDIUM"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 6.4, "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P"}}], "timeline": [{"time": "2023-07-10T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2023-07-10T00:00:00.000Z", "lang": "en", "value": "CVE reserved"}, {"time": "2023-07-10T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2023-07-27T13:02:19.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "dewanritik (VulDB User)", "type": "analyst"}], "references": [{"url": "https://vuldb.com/?id.233467", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/?ctiid.233467", "tags": ["signature"]}]}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T07:01:56.578Z"}, "title": "CVE Program Container", "references": [{"url": "https://vuldb.com/?id.233467", "tags": ["vdb-entry", "technical-description", "x_transferred"]}, {"url": "https://vuldb.com/?ctiid.233467", "tags": ["signature", "x_transferred"]}]}, {"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-10-15T17:29:02.650167Z", "id": "CVE-2023-3605", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-15T18:33:35.103Z"}}]}}