Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21777
HistoryOct 25, 2019 - 2:32 a.m.

Insecure Authentication Mechanism

2019-10-2502:32:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

61.9%

craftcms/cms is uses an insecure authentication mechanism. There is no account lockout after multiple failed attempts to log-in and the application does not rate-limit the elevated session password prompt, allowing an attacker to perform a brute-force attack on the log-in function and discover users’ passwords and gain access to the application.

CPENameOperatorVersion
craftcms/cmsle2.9.0
craftcms/cmsle3.1.6

0.002 Low

EPSS

Percentile

61.9%