CVE-2024-55653

MEDIUM

pwndoc <= 0.5.3 - Authenticated Denial of Service via Audit ID Handling

Title source: llm
STIX 2.1

Description

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the backend being unresponsive, the whole application becomes unusable for all users of the application. As of time of publication, no known patches are available.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0058
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
pwndoc_project/pwndoc < 0.9.0
Published Dec 10, 2024
Tracked Since Feb 18, 2026