Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h64j-vrf9-jpc3

Опубликовано: 16 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

EPSS

Процентиль: 23%
0.00302
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 7.5
nvd
25 дней назад

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.

EPSS

Процентиль: 23%
0.00302
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-307