Vulnerabilities > CVE-2024-43042 - Improper Restriction of Excessive Authentication Attempts vulnerability in Pluck-Cms Pluck 4.7.18

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
pluck-cms
CWE-307
critical

Summary

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

Vulnerable Configurations

Part Description Count
Application
Pluck-Cms
1