We found results for “”
WS-2023-0074
Good to know:
Date: February 20, 2023
No Protection against Bruteforce attacks on Login page was found in kiwitcms/kiwi. The server should have block the continues request to avoid the DOS attacks. and eventually we can login with the correct password without any blocking message. The issue is patched in version 12.0
Language: Python
Severity Score
Severity Score
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
CWE-770Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | PHYSICAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |