gist.github.com
https://gist.github.com/Gryffinbit/c0b37c6caae4844d4f59368e454d3e46 CVE-2024-48176
CRITICAL
Record summary
CVE-2024-48176 has a selected CVSS score of 9.8 (critical).
Description
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
lylme_spageBrowse lylme / lylme_spageDefault status: unknown | CVE List | 1.9.5 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-48176