In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Signinghub | Ascertia | * | 8.6.8 (including) |