PT-2018-13692 · Gleez · Gleez Cms
Natstheway
·
Published
2018-09-07
·
Updated
2019-10-03
·
CVE-2018-16703
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gleez CMS version 1.2.0
Description
The issue is related to insufficient server-side access control and login attempt limit enforcement on the login page. This could allow an unauthenticated, remote attacker to perform multiple user enumerations by sending modified login attempts to the Portal login page, such as navigating to the
user/4 URI. An exploit could enable the attacker to identify existing users and perform brute-force password attacks.Recommendations
For Gleez CMS version 1.2.0, consider temporarily restricting access to the login page or implementing additional server-side access controls to minimize the risk of exploitation. Restricting the number of login attempts from a single IP address within a certain time frame can also help mitigate the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gleez Cms