CVE-2024-47654

HIGH

Shilpi Client Dashboard - DoS

Title source: llm
STIX 2.1

Description

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-799
Status published
Products (1)
shilpisoft/client_dashboard < 9.7.0
Published Oct 04, 2024
Tracked Since Feb 18, 2026