Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjhr-gw79-v8fh

Опубликовано: 06 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863