0xsu3ks / CVE-2023-1665

CVE-2023-1665 - Twake App

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-1665 Brute Force on Twake App (Open Source Version of Microsoft Teams) < v2023.Q1.1223


CVSS: 7.8

Collaboration App, Twake (https://twake.app) before versions v2023.Q1.1223 does not restrict unauthenticated login attempts allowing for brute force attacks at the login page.

At the time of this report Twake has over 1 million Docker Pulls (source: https://github.com/linagora/Twake)

Submitted through platform huntr.dev

Vulnerability discovered and reported by Kevin Suckiel (@0xsu3ks) January, 2023.

About

CVE-2023-1665 - Twake App