ID |
CVE-2024-48143
|
Sažetak |
A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders. |
Reference |
|
CVSS |
Base: | 9.1 |
Impact: | 5.2 |
Exploitability: | 3.9 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
HIGH |
HIGH |
|
CVSS vektor |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Zadnje važnije ažuriranje |
25-10-2024 - 18:35 |
Objavljeno |
24-10-2024 - 19:15 |