cesargb/laravel-magiclink is vulnerable to Improper Restriction of Excessive Authentication Attempts
74
High Risk
The access code challenge for a protected magic link checks a submitted code with Hash::check() and has no attempt counter, lockout, or delay, and the route level rate limit is off by default and keyed by IP rather than by link. Anyone holding a valid access code protected magic link URL can submit unlimited guesses against that link from any IP until the code is found. A correct guess against a link protected with LoginAction gives full authentication as the victim. The fix throttles wrong guesses per magic link and returns a 429 response with a Retry-After header after repeated failures within a configurable window.
You are affected if you are using a version that falls within the vulnerable range and you protect a magic link with an access code.
cesargb/laravel-magiclink is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 2.14.0 - 2.28.0.
Upgrade the cesargb/laravel-magiclink library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.