CVE-2025-54320

MEDIUM

Ascertia Signinghub < 8.6.8 - Resource Allocation Without Limits

Title source: rule

Description

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

Exploits (1)

nomisec WRITEUP
by saykino · poc
https://github.com/saykino/CVE-2025-54320

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-770
Status published
Products (1)
ascertia/signinghub < 8.6.8
Published Nov 18, 2025
Tracked Since Feb 18, 2026