63moons

Wave 2.0

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 04.11.2024 13:17:05
  • Zuletzt bearbeitet 08.11.2024 15:19:48

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could l...

  • EPSS 0.48%
  • Veröffentlicht 04.11.2024 13:17:05
  • Zuletzt bearbeitet 08.11.2024 15:19:32

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user O...

  • EPSS 0.12%
  • Veröffentlicht 04.11.2024 13:17:05
  • Zuletzt bearbeitet 22.11.2024 12:15:19

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform ma...

  • EPSS 0.11%
  • Veröffentlicht 04.11.2024 13:17:05
  • Zuletzt bearbeitet 08.11.2024 15:18:23

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API r...

  • EPSS 0.3%
  • Veröffentlicht 04.11.2024 13:17:05
  • Zuletzt bearbeitet 06.11.2024 15:59:22

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during t...

  • EPSS 0.06%
  • Veröffentlicht 04.11.2024 13:17:04
  • Zuletzt bearbeitet 22.11.2024 12:15:19

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/pa...