CVE-2024-55653 describes a denial-of-service vulnerability in PwnDoc, a penetration test report generator, affecting versions up to and including 0.5.3. An authenticated attacker can crash the backend by triggering an UnhandledPromiseRejection on audits, rendering the application unusable for all users. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network attack vector with low complexity and high availability impact, but no confidentiality or integrity impact. There is currently no public exploit code, Metasploit module, or Nuclei template available, and it is not listed on the CISA KEV catalog, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.0CPE matchmatch criteria | cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.