PT-2024-40355 · Packagist · Typo3/Cms

Published

2024-05-30

·

Updated

2024-05-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned
Description The issue concerns a brute force protection mechanism in the backend login system. This mechanism pauses for 5 seconds when incorrect credentials are provided. However, it is possible to bypass this pause by forging a special request, which makes it more feasible to conduct brute force attacks on backend editor credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

GHSA-JQR8-Q455-XX45

Affected Products

Typo3/Cms