Описание
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.
Ссылки
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.1 (включая)
cpe:2.3:a:monstra:monstra:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00345
Низкий
5 Medium
CVSS2
Дефекты
CWE-255
Связанные уязвимости
github
больше 3 лет назад
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.
EPSS
Процентиль: 57%
0.00345
Низкий
5 Medium
CVSS2
Дефекты
CWE-255