CVE-2019-15929

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

Build bespoke content experiences with Craft.
GitHubGitHub
3.58K