PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the backend being unresponsive, the whole application becomes unusable for all users of the application. As of time of publication, no known patches are available.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Apr 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pwndoc Project
Pwndoc Project pwndoc |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:* | |
Vendors & Products |
Pwndoc Project
Pwndoc Project pwndoc |
Wed, 11 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Dec 2024 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the backend being unresponsive, the whole application becomes unusable for all users of the application. As of time of publication, no known patches are available. | |
Title | pwndoc's UnhandledPromiseRejection on audits causes Denial of Service (DoS) | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-11T16:04:21.230Z
Reserved: 2024-12-10T14:47:08.666Z
Link: CVE-2024-55653

Updated: 2024-12-11T16:04:17.576Z

Status : Analyzed
Published: 2024-12-10T23:15:06.410
Modified: 2025-04-18T17:35:00.030
Link: CVE-2024-55653

No data.