Description
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
before 27-06-2025
Credits
Humza Ahmad
Max van der Horst
References
csirt.divd.nl/CVE-2025-36758
csirt.divd.nl/DIVD-2025-00015