CVE-2024-48143

critical

Description

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.

References

https://github.com/soursec/CVEs/tree/main/CVE-2024-48143

https://digitory.com/multi-channel-integrated-pos/

Details

Source: Mitre, NVD

Published: 2024-10-24

Updated: 2024-10-25

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity: Critical