PT-2024-33003 · Digitory · Digitory Multi Channel Integrated Pos

Sourajeet Majumder

·

Published

2024-10-24

·

Updated

2024-10-25

·

CVE-2024-48143

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Digitory Multi Channel Integrated POS version 1.0
Description The issue is related to a lack of rate limiting in the OTP validation component, which allows attackers to gain access to the ordering system. This can lead to an excessive amount of food orders being placed.
Recommendations For Digitory Multi Channel Integrated POS version 1.0, consider implementing rate limiting in the OTP validation component to prevent excessive access to the ordering system.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2024-48143

Affected Products

Digitory Multi Channel Integrated Pos