CVE-2024-9953
MEDIUMCERT VINCE <3.0.8 - DoS
Title source: llmDescription
A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.
Scores
CVSS v3
4.9
EPSS
0.0019
EPSS Percentile
41.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
cert/vince
< 3.0.8
Timeline
Published
Oct 14, 2024
Tracked Since
Feb 18, 2026