PT-2025-5850 · Sylius · Sylius
Published
2025-02-06
·
Updated
2025-02-06
·
CVE-2024-57610
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Sylius version 2.0.2
Description
A rate limiting issue allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use firewalls, rate-limiting middleware, or authentication providers for that functionality.
Recommendations
For Sylius version 2.0.2, consider using firewalls, rate-limiting middleware, or authentication providers to mitigate the risk of brute-force attacks, as the Sylius core software does not address this functionality.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sylius