This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/ flooding on the targeted system.
History

Fri, 14 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Feb 2025 11:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/ flooding on the targeted system.
Title No Rate Limiting Vulnerability in RupeeWeb trading platform
Weaknesses CWE-799
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2025-02-14T16:27:38.618Z

Reserved: 2025-02-12T11:42:37.480Z

Link: CVE-2025-26524

cve-icon Vulnrichment

Updated: 2025-02-14T16:27:28.855Z

cve-icon NVD

Status : Received

Published: 2025-02-14T12:15:29.887

Modified: 2025-02-14T12:15:29.887

Link: CVE-2025-26524

cve-icon Redhat

No data.