Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-6427 +1 in the same advisory: …6426 | Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-6425 +1 in the same advisory: …6424 | Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" and in the parameters "UserName= &Password= &ConfirmPassword= ". NVD description · AI analysis pending | 9.1 group max | <1% |
| — |