A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
References
| Link | Resource |
|---|---|
| http://ascertia.com | Product |
| http://signinghub.com | Product |
| https://github.com/saykino/CVE-2025-56224 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-10-20 13:15
Updated : 2025-10-27 13:45
NVD link : CVE-2025-56224
Mitre link : CVE-2025-56224
CVE.ORG link : CVE-2025-56224
JSON object : View
Products Affected
ascertia
- signinghub
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
