CVE-2024-47654
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.49%
- CWE
- CWE-799
- Published
- 2024-10-04
- Last modified
- 2026-03-13
Affected products
- Shilpi Computers Client Dashboard
Weakness type
Related vulnerabilities
- CVE-2026-85586 — phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
- CVE-2026-54738 — Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo
- CVE-2026-75773 — karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
- CVE-2026-19898 — VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication
- CVE-2026-19897 — mangroup dtale Login Endpoint auth.py login excessive authentication
- CVE-2026-19895 — opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
- CVE-2024-23565 — HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail...
- CVE-2026-33434 — Wazuh: Rate Limit Bypass via /events Endpoint