Lucene search

K
cvelistMitreCVELIST:CVE-2020-28206
HistoryDec 02, 2020 - 6:34 p.m.

CVE-2020-28206

2020-12-0218:34:06
mitre
www.cve.org
5
bitrix24
framework
user enumeration
brute-force attacks
vulnerability
remote user

EPSS

0.004

Percentile

73.6%

An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An β€œUser enumeration and Improper Restriction of Excessive Authentication Attempts” vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.

EPSS

0.004

Percentile

73.6%

Related for CVELIST:CVE-2020-28206