Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-15367 — Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain unauthorized access. | Kitploit
Tools/GitHubGitHub/inflixim4be/cve-2020-15367
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationAuthentication
GitHubinflixim4be/cve-2020-15367

CVE-2020-15367

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain unauthorized access.

View Repository
1546 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-15367
Brute Force on Supravizio BPM 10.1.2


Description

Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

Exploitation

To exploit this vulnerability, it is necessary using the user enumeration vulnerability in Password Recovery (CVE-2020-15392) to enumerate the valid users and after could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account.

PoC

  • Login Page

  • Brute Force Login - Invalid User

  • Brute Force Login - Valid User
Download Tool