This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.
History

Wed, 16 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Shilpisoft
Shilpisoft client Dashboard
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Shilpisoft
Shilpisoft client Dashboard
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.
Title No Rate Limiting vulnerability
Weaknesses CWE-799
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:18:18.257Z

Updated: 2024-10-04T14:10:32.719Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47654

cve-icon Vulnrichment

Updated: 2024-10-04T14:10:24.912Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:11.680

Modified: 2024-10-16T15:17:33.227

Link: CVE-2024-47654

cve-icon Redhat

No data.