PT-2026-81287 · Ech0 · Ech0
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.7.3
Description
An authentication bypass exists in the 'PUT /api/echo/like/:id' endpoint, allowing unauthenticated attackers to increment engagement metrics without identity verification or rate limiting. By sending repeated requests, attackers can arbitrarily inflate the
fav count field for any known echo identifier, which compromises the integrity of social ranking systems and engagement metrics.Recommendations
Update to version 4.7.3 or later.
As a temporary workaround, restrict access to the 'PUT /api/echo/like/:id' endpoint to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ech0