CRITICAL 9.8 PyPI

Lin-CMS-Flask vulnerable to Improper Authentication

GHSA-h6r2-pgvx-683c · CVE-2020-18698 · PYSEC-2021-339

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component app/api/cms/user.py.

Ready to move

Start Securing

Free, no credit card | First findings in minutes