PT-2020-16946 · Bitrix · Bitrix24 Bitrix Framework
Published
2020-12-02
·
Updated
2020-12-04
·
CVE-2020-28206
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bitrix24 Bitrix Framework (1c site management) version 20.0
Description
An issue exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.
Recommendations
For version 20.0, consider restricting access to the admin login form to minimize the risk of exploitation. As a temporary workaround, consider implementing additional authentication measures, such as rate limiting or IP blocking, to prevent brute-force attacks.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitrix24 Bitrix Framework