CVE-2024-34695
MEDIUMDescription
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.
Is your site exposed to CVE-2024-34695?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-34695? +
How severe is CVE-2024-34695? +
How do I check if I'm vulnerable to CVE-2024-34695? +
Related Vulnerabilities
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an …
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation …
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 …