PT-2025-40867 · Unknown · Web Application Crede

CVE-2025-58587

·

Publicado

2025-10-06

·

Atualizado

2025-10-06

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Web Application Crede (affected versions not specified)
Description The application lacks adequate protection against brute-force attacks on authentication. Specifically, it does not limit the number of failed login attempts within a defined timeframe, potentially allowing attackers to guess user credentials. The API endpoint used for authentication is susceptible to this type of attack. The vulnerable parameters involved in the authentication process include username and password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-58587

Produtos afetados

Web Application Crede