CVE-2024-35539
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.
- Affected products
- Typecho
- Typecho
- = 1.3.0
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.4% (71th percentile)
- Weakness
- CWE-290
- NVD status
- Analyzed
- Published
- 2024-08-19
CVE-2024-35539 at NVD
4 known exploits for CVE-2024-35539
Proof-of-concept code and exploit modules indexed by Sploitus