TROYANOSYVIRUS
Volver a CVEs

CVE-2025-54321

CRITICAL
9.8

Descripcion

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado11/18/2025
Ultima modificacion11/20/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

ascertia:signinghub

Debilidades (CWE)

CWE-799

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.