Vulnerabilities > CVE-2021-31646 - Improper Restriction of Excessive Authentication Attempts vulnerability in Gestsup

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
gestsup
CWE-307

Summary

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

Vulnerable Configurations

Part Description Count
Application
Gestsup
1