{"id":"CVE-2025-52392","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-52392","summary":"Soosyze CMS's /user/login endpoint missing rate-limiting and lockout mechanisms","details":"Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability corresponds to CWE-307: Improper Restriction of Excessive Authentication Attempts.","published":"2025-08-13T15:30:34Z","modified":"2025-08-20T16:28:33.840146Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"soosyze/soosyze","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52392"},{"type":"WEB","url":"https://github.com/soosyze/soosyze/issues/269"},{"type":"WEB","url":"https://beafn28.gitbook.io/beafn28/cve/brute-force-login-vulnerability-in-soosyze-cms-2.0-cve-2025-52392"},{"type":"PACKAGE","url":"https://github.com/soosyze/soosyze"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52416"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-20T16:28:33.840146Z"}}