StevenAmador / CVE-2022-2650

Improper Restriction of Excessive Authentication Attempts (Brute Force) on wger workout application

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2022-2650 Brute Force on wger workout application v2.0


Open-source workout application, wger v2.0, does not restrict unauthenticated login attempts allowing for brute force attacks at the login page.

Submitted through platform huntr.dev

Vulnerability discovered and reported by Steven Amador (@HackinKraken) July, 2022.

http://stevenamador.com

About

Improper Restriction of Excessive Authentication Attempts (Brute Force) on wger workout application