Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41882
HistoryJul 31, 2023 - 9:41 a.m.

Denial Of Service (DoS)

2023-07-3109:41:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
denial of service
getkirby/cms
vulnerability
user.php
validatepassword
remote attacker
application slowdown

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.1%

getkirby/cms is vulnerable to Denial of Service. The vulnerability exists in the validatePassword function in User.php because it does not limit the password length, which can cause CPU and memory resource exhaustion when hashing if the attacker submits a password thats the the max size of a request body, allowing a remote attacker to cause an application slowdown.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.1%

Related for VERACODE:41882