PT-2025-44022 · Unknown · Virtfusion
0Xfun
·
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-12310
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
VirtFusion versions through 6.0.2
Description
A security issue exists in VirtFusion that relates to improper restriction of excessive authentication attempts. The issue is located within the Email Change Handler component, specifically affecting unknown code within the
/account/ settings file. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed.Recommendations
Versions prior to 6.0.3 should be updated.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Virtfusion