Lucene search

K
osvGoogleOSV:GHSA-JQR8-Q455-XX45
HistoryMay 30, 2024 - 9:12 p.m.

TYPO3 Brute Force Protection Bypass in backend login

2024-05-3021:12:16
Google
osv.dev
16
typo3
brute force protection
backend login
credential security
software vulnerability

AI Score

7.1

Confidence

High

The backend login has a basic brute force protection implementation which pauses for 5 seconds if wrong credentials are given. This pause however could be bypassed by forging a special request, making brute force attacks on backend editor credentials more feasible.

AI Score

7.1

Confidence

High