Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
References
Link | Resource |
---|---|
https://github.com/daylightstudio/FUEL-CMS/commit/15934fdd309408640d1f2be18f93a8beadaa5e9b | Patch Third Party Advisory |
https://github.com/daylightstudio/FUEL-CMS/issues/581 | Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-09-09 15:15
Updated : 2021-09-20 17:14
NVD link : CVE-2021-38725
Mitre link : CVE-2021-38725
CVE.ORG link : CVE-2021-38725
JSON object : View
Products Affected
thedaylightstudio
- fuel_cms
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts