PT-2024-37619 · Mesbook · Mesbook
David Utón Amaya
·
Published
2024-07-03
·
Updated
2024-07-07
·
CVE-2024-6427
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MESbook version 202221021.03
Description
The issue is related to an Uncontrolled Resource Consumption vulnerability. An unauthenticated remote attacker can use the
message parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself. This could lead to resource consumption and potentially disable the application.Recommendations
For version 202221021.03, consider disabling the use of the
message parameter until a patch is available to prevent exploitation. As a temporary workaround, restrict access to the application to minimize the risk of resource consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mesbook