Critical severity9.8NVD Advisory· Published Aug 28, 2023· Updated Jun 17, 2026
CVE-2023-40767
CVE-2023-40767
Description
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpjabbers:make_an_offer_widget:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpjabbers:make_an_offer_widget:1.0:*:*:*:*:*:*:*
- (no CPE)range: <=1.0
- PHPJabbers/Make an Offer Widgetdescription
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.