PT-2025-38231 · Thorium · Thorium
CVE-2025-35432
·
Publicado
2025-08-21
·
Atualizado
2025-09-18
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Thorium versions prior to 1.1.1
Description
Thorium does not limit the rate of requests to send account verification email messages. This allows a remote, unauthenticated attacker to send an unlimited number of messages to a user awaiting verification.
Recommendations
Update to version 1.1.1 or later to implement the default rate limit of 10 minutes for account verification email requests.
Exploit
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Thorium