PT-2025-25574 · Weblate · Weblate
Obscuredeer
·
Published
2025-06-16
·
Updated
2025-07-16
·
CVE-2025-47951
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.12
Description
The verification of the second factor was not subject to rate limiting, allowing an attacker with valid credentials to automate OTP guessing via the second factor endpoint.
Recommendations
For versions prior to 5.12, update to version 5.12 to resolve the issue. As a temporary workaround, consider restricting access to the second factor endpoint to minimize the risk of exploitation.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate