Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

Lin-CMS-Flask vulnerable to Improper Authentication

GHSA-h6r2-pgvx-683c · CVE-2020-18698 · PYSEC-2021-339

Published · Modified

Description

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component app/api/cms/user.py.

Ready to move

Start Securing

Free, no credit card | First findings in minutes