CVE-2023-30458: Medicine Tracker System Project Medicine Tracker System
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.
Affected products
- Medicine Tracker System Project Medicine Tracker System: version 1.0 only
Published 2023-04-24. Last modified 2026-06-17.