Critical severity9.8NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026
CVE-2020-18698
CVE-2020-18698
Description
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:talelin:lin-cms-flask:0.1.1:*:*:*:*:*:*:*
- Lin-CMS-Flask/Lin-CMS-Flaskdescription
- ghsa-coords
Patches
Vulnerability mechanics
References
5- github.com/TaleLin/lin-cms-flask/issues/27nvdExploitThird Party AdvisoryWEB
- cwe.mitre.org/data/definitions/307.htmlnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-h6r2-pgvx-683cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-18698ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/lin-cms/PYSEC-2021-339.yamlghsaWEB
News mentions
0No linked articles in our index yet.