A vulnerability in Kaiten version 57.131.12 and earlier...
Critical severity
Unreviewed
Published
Oct 1, 2024
to the GitHub Advisory Database
•
Updated Oct 1, 2024
Description
Published by the National Vulnerability Database
Oct 1, 2024
Published to the GitHub Advisory Database
Oct 1, 2024
Last updated
Oct 1, 2024
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.
References