CVE-2022-37145
08.09.2022, 01:15
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.Enginsight
| Vendor | Product | Version |
|---|---|---|
| plextrac | plextrac | 𝑥 < 1.17.0 |
𝑥
= Vulnerable software versions