CRITICAL 9.8 PyPI
web2py is vulnerable to password brute-force attack
GHSA-gv85-wgxc-vc56 · CVE-2016-10321 · PYSEC-2026-569
Published · Modified
Description
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
Ready to move
Start Securing
Free, no credit card | First findings in minutes