Описание
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.10.14 (исключая)
cpe:2.3:a:huntflow:huntflow_enterprise:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01361
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307
Связанные уязвимости
github
около 4 лет назад
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.
EPSS
Процентиль: 80%
0.01361
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307