Impact
Allocation of resources without limits or throttling in BizimHesap Information Systems' Online Pre-Accounting Software permits unbounded resource consumption. The vulnerability allows an attacker to trigger excessive allocation, potentially leading to denial of service by exhausting memory, disk, or other system resources. It is a classic resource allocation flaw classified as CWE-770.
Affected Systems
BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software, versions up to and including 17072026, are affected by this uncontrolled allocation mechanism.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS of less than 1% suggests low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote: an attacker uploads large or numerous files to trigger unlimited allocation, which can or disrupt service availability.
OpenCVE Enrichment