Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq9x-w82r-rhmc

Опубликовано: 13 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 5.4

Описание

Soosyze CMS's /user/login endpoint missing rate-limiting and lockout mechanisms

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability corresponds to CWE-307: Improper Restriction of Excessive Authentication Attempts.

Пакеты

Наименование

soosyze/soosyze

composer
Затронутые версииВерсия исправления

<= 2.0.0

Отсутствует

EPSS

Процентиль: 75%
0.00906
Низкий

7.7 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.4
nvd
6 месяцев назад

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability corresponds to CWE-307: Improper Restriction of Excessive Authentication Attempts.

EPSS

Процентиль: 75%
0.00906
Низкий

7.7 High

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-307