Vulnerability Description
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huntflow | Huntflow Enterprise | < 3.10.14 |
Related Weaknesses (CWE)
References
- https://gist.github.com/andrey-lomtev/4ec9004101152ea9d0043a09d59498a6ExploitThird Party Advisory
- https://gist.github.com/andrey-lomtev/4ec9004101152ea9d0043a09d59498a6ExploitThird Party Advisory
FAQ
What is CVE-2021-37934?
CVE-2021-37934 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple...
How severe is CVE-2021-37934?
CVE-2021-37934 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-37934?
Check the references section above for vendor advisories and patch information. Affected products include: Huntflow Huntflow Enterprise.