PT-2023-21990 · Unknown · Concrete Cms
0X0002
·
Publicado
2023-04-28
·
Atualizado
2025-01-30
·
CVE-2023-28821
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Concrete CMS (previously concrete5) versions prior to 9.1
Description
The issue is related to the lack of a rate limit for password resets in Concrete CMS. This could potentially allow for brute-force attacks on user passwords.
Recommendations
For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider implementing a custom rate limit for password resets until a patch is available. Restrict access to the password reset functionality to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Concrete Cms