Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6427

Опубликовано: 03 июл. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mesbook:mesbook:20221021.03:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00625
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
github
около 1 года назад

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

EPSS

Процентиль: 69%
0.00625
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770