CVE-2026-49870
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
5.9 / 10
Vulnerability Description
Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
composer
Product
snipe/snipe-it
Discussion (0)
Add Comment
No comments yet. Be the first!