CVE-2024-41276
概要

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.

公表日 2024年10月1日23:15
登録日 2024年10月2日12:00
最終更新日 2024年10月4日22:51
関連情報、対策とツール
共通脆弱性一覧