← Back to CVE search

CVE-2024-58360

stoatchat

Description

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.

CVSS 6.5EPSS 0.259%Risk 0.67
View source
Published
2026-07-16 13:16:23
Affected versions
<0.7.8
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L