CVE-2024-47654

HIGH

Shilpi Client Dashboard < 9.7.0 - Unauthenticated OTP Bombing via API Endpoint

Title source: llm
STIX 2.1

Description

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-799
Status published
Products (1)
shilpisoft/client_dashboard < 9.7.0
Published Oct 04, 2024
Tracked Since Feb 18, 2026