Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48176

Опубликовано: 05 нояб. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lylme:lylme_spage:1.9.5:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863