
Proof-of-concept for CVE-2025-54320: an email bombing vulnerability in Ascertia SigningHub's Invite User API due to missing rate limiting, allowing authenticated remote attackers to flood target inboxes.
Description
The invitation API does not implement rate limiting for the target email address. This allows for an Email Bombing attack.
CVSS Score: 7.1 (High)
Attack Type
Affected Versions
Vendor of Product
Affected Product Code Base
Affected Component
Mitigations
Vulnerability Details
Fixed versions
Discovered By: