This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/ flooding on the targeted system.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/ flooding on the targeted system. | |
Title | No Rate Limiting Vulnerability in RupeeWeb trading platform | |
Weaknesses | CWE-799 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2025-02-14T16:27:38.618Z
Reserved: 2025-02-12T11:42:37.480Z
Link: CVE-2025-26524

Updated: 2025-02-14T16:27:28.855Z

Status : Received
Published: 2025-02-14T12:15:29.887
Modified: 2025-02-14T12:15:29.887
Link: CVE-2025-26524

No data.