Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PlexTrac API 安全漏洞
Vulnerability Description
PlexTrac是美国PlexTrac公司的一个渗透测试报告和管理平台。 PlexTrac API 1.17.0之前版本存在安全漏洞,该漏洞源于没有限制过多的MFA TOTP提交尝试,拥有有效用户名和密码的未经身份验证的远程攻击者可以强行通过MFA保护,以目标用户身份登录。
CVSS Information
N/A
Vulnerability Type
N/A