Unknown · Th Wildau Covid-19 Contact Tracing · CVE-2021-33831
Name of the Vulnerable Software and Affected Versions:
TH Wildau COVID-19 Contact Tracing application through 2021-09-01
Description:
The issue is related to Incorrect Access Control in the `api/account/register` endpoint. An attacker can create 500 random users within 2500 seconds, potentially interfering with the tracing of infection chains.
Recommendations:
For the TH Wildau COVID-19 Contact Tracing application through 2021-09-01, consider temporarily restricting access to the `api/account/register` endpoint to prevent exploitation until a fix is available. As a mitigation measure, limit the number of user registrations within a certain time frame to prevent abuse. At the moment, there is no information about a newer version that contains a fix for this issue.