Executive brief
The Online Library Management System, a web application used for managing library resources and user records, contains a security flaw in its administrative login page. The system fails to limit the number of times a user can attempt to log in, allowing an attacker to repeatedly guess passwords until they gain access. If successful, an attacker could take full control of the library system, potentially accessing sensitive user data or disrupting operations.
Technical details
A 'No Rate Limiting' vulnerability (CWE-250/CWE-307) exists in the adminlogin.php component of Online Library Management System v3.0. The application does not implement account lockout mechanisms or request throttling on the login function, allowing for unauthenticated, automated brute-force attacks via the network. An attacker can use tools like Burp Suite Intruder to iterate through common usernames and passwords without restriction. Successful exploitation allows the attacker to obtain valid administrative credentials, leading to unauthorized access to the admin dashboard and full system compromise. As of the advisory date, users are advised to manually implement rate limiting and strong password policies.
Affected products
- PHPGurukul Online Library Management System 3.0
Timeline
- 2025-09-16: disclosed: Initial NVD publication
- 2025-09-17: advisory: CISA-ADP enrichment and CVSS assessment provided