Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54321

Опубликовано: 18 нояб. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ascertia:signinghub:*:*:*:*:*:*:*:*
Версия до 8.6.8 (включая)

EPSS

Процентиль: 20%
0.00065
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-799

Связанные уязвимости

CVSS3: 9.8
github
3 месяца назад

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

EPSS

Процентиль: 20%
0.00065
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-799