index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password]…
mitre·CWE-307·Published 2018-11-26