You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
No protection against brute-force attacks on login page
High severity
GitHub Reviewed
Published
Feb 15, 2023
in
kiwitcms/Kiwi
•
Updated Feb 24, 2023
Impact
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
Patches
Users should upgrade to v12.0 or later.
Workarounds
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
References
Disclosed by spyata
References