VulnerabilityAnalyzed
CVE-2024-48176
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control.
CRITICAL 9.8EPSS 0.47%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- lylme/lylme spage
- Source
- cve@mitre.org
References
- https://gist.github.com/Gryffinbit/c0b37c6caae4844d4f59368e454d3e46Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.