Brute Force Vulnerability in Fuel CMS by Daylight Studio
CVE-2021-38725

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2021

What is CVE-2021-38725?

Fuel CMS version 1.5.0 contains a vulnerability in the Login module that allows attackers to perform brute force attacks. This flaw can enable unauthorized access attempts through repeated login submissions, making it essential for users and administrators to implement safeguards such as account lockout mechanisms or CAPTCHA to mitigate the risk of compromise. For further insights, refer to the documentation and ongoing discussions in the community.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.