ZeroHour

CVE-2025-54320

CVSS 3.1
4.3 medium
EPSS
<1%p26
Published
()
Modified
Description

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

Vendors
ascertia
Products
signinghub
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.