PT-2018-13692 · Gleez · Gleez Cms

Natstheway

·

Published

2018-09-07

·

Updated

2019-10-03

·

CVE-2018-16703

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gleez CMS version 1.2.0
Description The issue is related to insufficient server-side access control and login attempt limit enforcement on the login page. This could allow an unauthenticated, remote attacker to perform multiple user enumerations by sending modified login attempts to the Portal login page, such as navigating to the user/4 URI. An exploit could enable the attacker to identify existing users and perform brute-force password attacks.
Recommendations For Gleez CMS version 1.2.0, consider temporarily restricting access to the login page or implementing additional server-side access controls to minimize the risk of exploitation. Restricting the number of login attempts from a single IP address within a certain time frame can also help mitigate the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16703

Affected Products

Gleez Cms