Brute Force Attacks Possible Due to Lack of Login Restrictions
CVE-2024-43042
9.8CRITICAL
What is CVE-2024-43042?
A security issue has been identified in Pluck CMS version 4.7.18, which fails to limit repeated failed login attempts. This oversight enables attackers to utilize brute force methods to gain unauthorized access. Without adequate protections in place to restrict login attempts, the risk of compromised accounts increases significantly, potentially leading to data breaches and further exploitation. Web application developers and administrators using this version are urged to implement additional security measures to mitigate this vulnerability.
