CVE-2023-23755

HIGH7.5EPSS 0.01%

[20230502] - Core - Bruteforce prevention within the mfa screen

Published: 4/3/2025Modified: 5/20/2025

Description

An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (2)