Логотип exploitDog
bind:CVE-2025-29998
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-29998

Количество 3

Количество 3

nvd логотип

CVE-2025-29998

11 месяцев назад

This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

EPSS: Низкий
github логотип

GHSA-cwqf-2qf9-9mh4

11 месяцев назад

This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

EPSS: Низкий
fstec логотип

BDU:2026-00046

11 месяцев назад

Уязвимость компонента API Endpoint бэк-офисного приложения Rising Technosoft CAP Back Office Application, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-29998

This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

0%
Низкий
11 месяцев назад
github логотип
GHSA-cwqf-2qf9-9mh4

This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

0%
Низкий
11 месяцев назад
fstec логотип
BDU:2026-00046

Уязвимость компонента API Endpoint бэк-офисного приложения Rising Technosoft CAP Back Office Application, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
0%
Низкий
11 месяцев назад

Уязвимостей на страницу