← Back

CVE-2024-48176

nvd nist
Published: Nov 5, 2024Modified: May 1, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

Affected (1)

Products: Lylme: Lylme Spage
1 product
Lylme Spage
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.9.5

References (1)

Timeline

No history available yet.