Vulnerability Description
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ascertia | Signinghub | <= 8.6.8 |
Related Weaknesses (CWE)
References
- https://github.com/saykino/CVE-2025-54320Third Party Advisory
- https://www.ascertia.com/company/vulnerability-disclosure-policy/Vendor Advisory
FAQ
What is CVE-2025-54320?
CVE-2025-54320 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating ...
How severe is CVE-2025-54320?
CVE-2025-54320 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54320?
Check the references section above for vendor advisories and patch information. Affected products include: Ascertia Signinghub.