Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://github.com/pluck-cms/pluck | product |
https://drive.google.com/file/d/1FnLCFP8xDrE1e_4Ft_TZ7VhC-JBkpsL0/view?usp=sharing | third party advisory exploit |