Description
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Remediation
References
Related Vulnerabilities
WordPress Plugin Zedity:The Easiest Way To Create Posts & Pages Cross-Site Scripting (2.5.0)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3554)
Internet Information Services Other Vulnerability (CVE-2004-0205)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (6.0.4)