2024-12-08 03:06:42 +00:00

64 lines
1.9 KiB
JSON

{
"id": "CVE-2024-48143",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-10-24T19:15:15.427",
"lastModified": "2024-10-25T18:35:09.327",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders."
},
{
"lang": "es",
"value": "La falta de limitaci\u00f3n de velocidad en el componente de validaci\u00f3n de OTP de Digitory Multi Channel Integrated POS v1.0 permite a los atacantes obtener acceso al sistema de pedidos y realizar una cantidad excesiva de pedidos de comida."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-307"
}
]
}
],
"references": [
{
"url": "https://digitory.com/multi-channel-integrated-pos/",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-48143",
"source": "cve@mitre.org"
}
]
}