Vulnerability Details CVE-2018-19548
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-force approach.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2018-19548
-
cpe:2.3:a:rudrasoftech:edusec:2.0.0
-
cpe:2.3:a:rudrasoftech:edusec:2.1.2
-
cpe:2.3:a:rudrasoftech:edusec:3.0.0
-
cpe:2.3:a:rudrasoftech:edusec:4.0.0
-
cpe:2.3:a:rudrasoftech:edusec:4.1.0
-
cpe:2.3:a:rudrasoftech:edusec:4.2.0
-
cpe:2.3:a:rudrasoftech:edusec:4.2.1
-
cpe:2.3:a:rudrasoftech:edusec:4.2.2
-
cpe:2.3:a:rudrasoftech:edusec:4.2.3
-
cpe:2.3:a:rudrasoftech:edusec:4.2.4
-
cpe:2.3:a:rudrasoftech:edusec:4.2.5
-
cpe:2.3:a:rudrasoftech:edusec:4.2.6