PT-2026-1823 · Shiori · Shiori
Published
2026-01-09
·
Updated
2026-01-17
·
CVE-2025-60538
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
shiori versions 1.7.4 and below
Description
A missing rate limit on the login page allows attackers to bypass authentication through brute-force attempts. The affected component is the login functionality, specifically the authentication process. The API endpoint involved is the login page. The vulnerability allows attackers to attempt multiple login requests without restriction, potentially guessing valid credentials.
Recommendations
Apply rate limiting to the login page to restrict the number of login attempts within a specific timeframe.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shiori