CRITICAL
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them
Published Oct 24, 2019
9.8
CRITICALCVSS 3.1
EPSS 1.75%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.