
Session-scoped TOTP rate limiting permits repeated verification attempts
FileRise versions before 3.23.0 stored failed TOTP verification attempts in PHP session state. The counter limited attempts within one session but did not persist across newly created sessions.
An attacker who already possesses a target account's valid primary credential could restart the login workflow, receive a new pending-login session, and restore the TOTP attempt allowance. Repeating this process permitted continued online TOTP guessing beyond the intended five-attempt limit.
The TOTP verification flow maintained its failure counter in $_SESSION. After five failed submissions, further attempts in that session returned HTTP 429.
However, successfully completing primary authentication in a new session created new pending-login state with a new TOTP failure counter. The previous account's TOTP failures were therefore not carried forward.
The issue also affected another pending-login TOTP handler that did not enforce the same durable limit. The remediation was consequently applied centrally across all pending-login TOTP verification paths.
This issue is classified as CWE-307: Improper Restriction of Excessive Authentication Attempts.
Exploitation requires possession of the target account's valid primary credential, such as a password obtained through credential reuse, phishing, or another compromise.
The vulnerability does not disclose credentials or immediately bypass TOTP. It permits continued automated TOTP guessing without a durable account-wide limit. A successful guess completes authentication with the privileges of the affected account, potentially including administrator privileges.
Accounts without TOTP enabled are not affected by this specific second-factor rate-limit issue.
FileRise 3.23.0 introduces centralized persistent TOTP attempt limiting:
Existing accounts, TOTP secrets, sessions, Docker installations, and deployment configuration require no migration.
Users should upgrade to FileRise 3.23.0 or later.
Thank you for the responsible disclosure and detailed reproduction steps.
We reviewed the TOTP verification workflow and confirmed the underlying issue. Failed TOTP submissions were limited only by a PHP session counter in the primary frontend verification endpoint. Repeating the successful primary-authentication step in a fresh session could therefore restore the second-factor attempt budget. Our review also identified another pending-login TOTP handler that did not apply the same attempt counter, so the remediation has been applied centrally across the verification paths rather than only to the reported endpoint.
The fix has been implemented for FileRise v3.23.0:
The account limit is five attempts in a 15-minute window. The source-wide limit is intentionally higher at 50 attempts in the same window to reduce false positives for shared networks. Existing accounts, TOTP secrets, sessions, Docker installations, and deployment configuration require no migration.
Credit: Pervin Zahidli (@ech0void ) Ref : https://github.com/error311/FileRise/security/advisories/GHSA-4hfj-6478-5cv7