No Protection against Bruteforce attacks on Login page in kiwitcms/kiwi


Reported on

Dec 3rd 2022

Description Webpage manager does not limit unsuccessful login attempts allowing Brute Forcing.

Proof of Concept

  1. Register the account.
  2. Logout the account and try to login with the different password.
  3. Take the request into Burp suite intruder, set the payload list to 30(for testing).
  4. The server is accepting each request and it not limiting the response.

The server should have block the continues request to avoid the DOS attacks. and eventually we can login with the correct password without any blocking message.

# Impact

The impact is unlimited password attempts leading to Brute Force attacks on the login page.


Sorry i could not find the correct permalink.

We are processing your report and will contact the kiwitcms/kiwi team within 24 hours. a year ago
We have contacted a member of the kiwitcms/kiwi team and are waiting to hear back a year ago
kiwitcms/kiwi maintainer validated this vulnerability a year ago
satya250 has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
kiwitcms/kiwi maintainer marked this as fixed in 12.0 with commit 0ed213 a year ago
The fix bounty has been dropped has been validated
This vulnerability has now been published a year ago
to join this conversation