Description

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the backend being unresponsive, the whole application becomes unusable for all users of the application. As of time of publication, no known patches are available.

INFO

Published Date :

2024-12-10T22:56:07.488Z

Last Modified :

2024-12-11T16:04:21.230Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-55653 vulnerability.

Vendors Products
Pwndoc Project
  • Pwndoc
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-55653.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact