macrozheng mall Improper Restriction of Excessive Authentication Attempts Vulnerability

Vulnerability

A vulnerability exists in macrozheng mall version 1.0.3 and prior, where the admin login component fails to adequately limit excessive authentication attempts. This flaw allows unauthenticated remote attackers to conduct brute force attacks, bypassing authentication. The vulnerability arises from improper management of authentication attempts, leaving the system open to exploitation.

Impact

Exploitation of this vulnerability could lead to unauthorized access through brute force authentication bypass, allowing attackers to gain administrative privileges.

Reproduction

To reproduce this vulnerability, initiate a brute force attack on the admin login page of the macrozheng mall application version 1.0.3 or earlier. The application does not properly limit the number of failed login attempts, allowing for repeated tries with different passwords. Monitor the response status and content length to confirm the bypass.

Added: Aug 8, 2025, 10:17 PM
Updated: Aug 8, 2025, 10:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.0
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.