PT-2026-81280 · Ech0 · Ech0
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.7.3
Description
The application registers the 'PUT /api/echo/like/:id' endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the
fav count counter of any echo, including private ones, by providing its UUID, which can be obtained from the 'GET /api/echo/page' feed. Because repeated requests are accepted without deduplication, each request triggers a database write and a four-key cache invalidation, enabling attackers to inflate popularity metrics and increase the load on the database and cache.Recommendations
Update to version 4.7.3.
Exploit
Fix
Missing Authorization
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ech0