Description
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5648 | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them. |
Github GHSA |
GHSA-wvr4-w6cw-4px8 | Craft CMS possibility of brute force attempts |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:03:32.465Z
Reserved: 2019-09-04T00:00:00.000Z
Link: CVE-2019-15929
No data.
Status : Modified
Published: 2019-10-24T16:15:20.127
Modified: 2024-11-21T04:29:45.250
Link: CVE-2019-15929
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA