Security Advisory

CVE-2024-48176

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-11-05 00:00:00
Last updated 2024-11-06 16:04:46
Assigner mitre
State PUBLISHED

Description

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.