Improper Control of Interaction Frequency
CVE-2024-57603
Summary
An issue in MaysWind/ezBookkeeping allows a remote attacker to escalate privileges via the lack of rate limiting. This issue affects versions prior to 0.8.0. This has the same fix as CVE-2024-57604.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- LOW
- LOW
- LOW
CWE-799 - Improper Control of Interaction Frequency
The software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
References
Advisory Timeline
- Published