Описание
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
Ссылки
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.6.8 (включая)
cpe:2.3:a:ascertia:signinghub:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00061
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 4.3
github
3 месяца назад
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
EPSS
Процентиль: 19%
0.00061
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-770