Description
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Affiliate Platform Multiple Vulnerabilities (6.3.9)
Oracle JRE CVE-2013-2383 Vulnerability (CVE-2013-2383)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5866)
WordPress Plugin Mingle Forum Multiple Cross-Site Scripting Vulnerabilities (1.0.33)
WordPress Plugin LinkedIn by BestWebSoft Cross-Site Scripting (1.0.4)