ZeroHour

CVE-2025-54321

CVSS 3.1
9.8 critical
EPSS
<1%p39
Published
()
Modified
Description

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

Vendors
ascertia
Products
signinghub
Weakness
CWE-799
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.