CVE-2024-47654

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*

History

16 Oct 2024, 15:17

Type Values Removed Values Added
First Time Shilpisoft client Dashboard
Shilpisoft
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-Other
Summary
  • (es) Esta vulnerabilidad existe en Shilpi Client Dashboard debido a la falta de limitación de velocidad y protección Captcha para solicitudes OTP en ciertos endpoints de API. Un atacante remoto no autenticado podría aprovechar esta vulnerabilidad enviando múltiples solicitudes OTP a través de endpoints de API vulnerables, lo que podría provocar el bombardeo de OTP en el sistema objetivo.
CPE cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory

04 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 13:15

Updated : 2024-10-16 15:17


NVD link : CVE-2024-47654

Mitre link : CVE-2024-47654

CVE.ORG link : CVE-2024-47654


JSON object : View

Products Affected

shilpisoft

  • client_dashboard
CWE
NVD-CWE-Other CWE-799

Improper Control of Interaction Frequency