stoatchat
- >= 0, < 0.7.8
A vulnerability exists in Stoatchat versions prior to 0.7.8, allowing unrestricted account creation. The application fails to enforce essential account creation protocols such as invite-only mode, email verification, captcha, and shield verification. This oversight enables attackers to generate an unlimited number of accounts using unverified email addresses, which could lead to increased denial-of-service risks and undermine the integrity of the service.
The vulnerability allows for unrestricted account creation, bypassing verification processes. This can lead to a higher risk of denial-of-service attacks and compromise the overall integrity of the service.
Users can upgrade to Stoatchat version 0.7.8 or downgrade to version 0.6.13. The patch for this vulnerability is included in the 0.7.8 release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.