CRITICAL 9.8 PyPI

web2py is vulnerable to password brute-force attack

GHSA-gv85-wgxc-vc56 · CVE-2016-10321 · PYSEC-2026-569

Published · Modified

Description

web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes