Critical severityNVD Advisory· Published Aug 16, 2021· Updated Aug 4, 2024
CVE-2020-18698
CVE-2020-18698
Description
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Lin-CMS-Flask/Lin-CMS-Flaskdescription
- ghsa-coords
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-h6r2-pgvx-683cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-18698ghsaADVISORY
- cwe.mitre.org/data/definitions/307.htmlghsax_refsource_MISCWEB
- github.com/TaleLin/lin-cms-flask/issues/27ghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/lin-cms/PYSEC-2021-339.yamlghsaWEB
News mentions
0No linked articles in our index yet.