CVE-2023-41885 is a low-severity information disclosure vulnerability affecting Piccolo ORM versions 0.120.0 and prior, allowing attackers to enumerate valid user accounts. This is due to insufficient information leakage protection in the BaseUser.login function. The vulnerability has a CVSS score of 5.3 (Medium) and requires no authentication or user interaction, making it easy to exploit. While not actively exploited and lacking public exploit code, the ease of exploitation and potential for password spray attacks against identified user lists warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.121.0CPE matchmatch criteria | cpe:2.3:a:piccolo-orm:piccolo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.