CVE-2024-58360
stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.45%
- CWE
- CWE-1173
- Published
- 2026-07-16
- Last modified
- 2026-07-18
Affected products
- stoatchat stoatchat
- stoatchat stoatchat
Weakness type
Related vulnerabilities
- CVE-2026-33674 — PrestaShop: Improper Use of Validation Framework
- CVE-2025-48490 — Laravel Rest Api has a Search Validation Bypass
- CVE-2025-3940 — Improper Use of Validation Framework
- CVE-2023-30949 — CVE-2023-30949
- CVE-2022-1414 — 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An...
- CVE-2020-1640 — Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.