CVE-2024-48176

CRITICAL

lylme_spage 1.9.5 - Incorrect Access Control via Login Brute Force

Title source: llm
STIX 2.1

Description

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
lylme/lylme_spage 1.9.5
Published Nov 05, 2024
Tracked Since Feb 18, 2026