GHSA-vq9x-w82r-rhmc

Suggest an improvement
Source
https://github.com/advisories/GHSA-vq9x-w82r-rhmc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-vq9x-w82r-rhmc/GHSA-vq9x-w82r-rhmc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vq9x-w82r-rhmc
Aliases
  • CVE-2025-52392
Published
2025-08-13T15:30:34Z
Modified
2025-08-20T16:28:33.840146Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Soosyze CMS's /user/login endpoint missing rate-limiting and lockout mechanisms
Details

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability corresponds to CWE-307: Improper Restriction of Excessive Authentication Attempts.

Database specific
{
    "cwe_ids": [
        "CWE-307"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-08-13T23:13:41Z",
    "nvd_published_at": "2025-08-13T14:15:31Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / soosyze/soosyze

Package

Name
soosyze/soosyze
Purl
pkg:composer/soosyze/soosyze

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0.0

Affected versions

1.*
1.0.0-alpha1
1.0.0-alpha2
1.0.0-alpha3
1.0.0-alpha4
1.0.0-alpha4.1
1.0.0-alpha5
1.0.0-alpha6
1.0.0-alpha6.1
1.0.0-alpha7
1.0.0-alpha7.1
1.0.0-alpha8
1.0.0-alpha9
1.0.0-beta1
1.0.0-beta1.1
1.0.0-beta1.2
1.0.0-beta2
1.0.0-beta2.1
1.0.0-beta2.2
1.0.0-beta2.3
1.0.0-beta2.4
1.0.0
1.0.1
1.0.2
2.*
2.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-vq9x-w82r-rhmc/GHSA-vq9x-w82r-rhmc.json"