GHSA-2hjh-495w-hmxc · Severity: medium · Ecosystem: composer — Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.
Conclusion & alert: CVE-2024-57610 is rated High Exploit Risk (77.6/100): CVSS High severity, with high exploitation likelihood (EPSS 9.77%, 93th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-27 | 9.74% | 9.77% | +0.03% |
| 2 | 2026-03-19 | 12.27% | 9.74% | -2.53% |
| 3 | 2026-03-18 | — | 12.27% | — |
Full EPSS history (27 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-2hjh-495w-hmxc · Severity: medium · Ecosystem: composer — Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
| URL | Tags |
|---|---|
| https://github.com/Sylius/Sylius | Product |
| https://github.com/nca785/CVE-2024-57610 | Exploit Third Party Advisory |
| https://sylius.com/ | Product |