No set limit to try to login in "https://auth.nextcloud.com/auth/realms/master/protocol/openid-connect/auth" page.
Unknown
Vulnerability Details
Hi.
I checked the "https://nextcloud.com" page, and try to go to wp-admin page.
Then, I found the login page "https://auth.nextcloud.com/auth/realms/master/protocol/openid-connect/auth"
In this page, I tried to login more than 10 times!(manually)
I think that I can try to brute force to this login page, because it's no limit to try to login.
You should be better to set the limit to try to login.
## Impact
an attacker can try to brute force attack to login the page until he can success to login.
Actions
View on HackerOneReport Stats
- Report ID: 855304
- State: Closed
- Substate: informative
- Upvotes: 3