vendor:
Bludit CMS
by:
ColdFusionX (Mayank Deshmukh)
9.8
CVSS
CRITICAL
Bruteforce Mitigation Bypass
287
CWE
Product Name: Bludit CMS
Affected Version From: <= 3.9.2
Affected Version To: <= 3.9.2
Patch Exists: YES
Related CWE: CVE-2019-17240
CPE: a:bludit:bludit:3.9.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Bludit <= 3.9.2 - Bruteforce Mitigation Bypass
This exploit is a python script which bypasses the authentication bruteforce mitigation of Bludit CMS version 3.9.2 and below. It takes the URL of the login page, username and password dictionaries as arguments and tries to brute force the login page. If successful, it prints a success message and exits.
Mitigation:
Upgrade to the latest version of Bludit CMS or apply the patch provided by the vendor.