Skip to main content

Improper Control of Interaction Frequency

CVE-2024-57603

Severity Medium
Score 6.3/10

Summary

An issue in MaysWind/ezBookkeeping allows a remote attacker to escalate privileges via the lack of rate limiting. This issue affects versions prior to 0.8.0. This has the same fix as CVE-2024-57604.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • LOW

CWE-799 - Improper Control of Interaction Frequency

The software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Advisory Timeline

  • Published