peter bassill · operator
$ cve CVE-2024-35539 JSON

CVE-2024-35539 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 1.4% (pctl 73)

Patch early

A public exploit exists.

Description

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS1.45% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploityes
Published2024-08-19
Last modified2026-06-17

Affected (1)

VendorProduct
typechotypecho

Public exploits

SourceTitleDate
exploit-dbTypecho 1.3.0 - Race Condition2025-04-10

References

→ the Explorer  ·  watch your stack  ·  NVD