CVE-2025-3556 is a problematic vulnerability in ScriptAndTools eCommerce-website-in-PHP version 3.0, specifically affecting the /admin/login.php file. This flaw allows for improper restriction of excessive authentication attempts, potentially leading to brute-force attacks. The vulnerability has a CVSS score of 8.1 (HIGH), indicating a significant risk. While the attack can be launched remotely, its complexity and exploitation difficulty are rated as high, suggesting a more sophisticated attacker is required. A successful exploit could lead to high impact on confidentiality, integrity, and availability. Despite public disclosure of the exploit, there is no evidence of active exploitation (KEV: No), nor are there readily available Metasploit, Nuclei, or ExploitDB modules. Community discussion and media coverage are minimal, suggesting low public awareness or immediate concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:scriptandtools:ecommerce-website-in-php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.