← back
CVE-2024-10599mediumCWE-400

Tongda OA 2017 package_static_resources.php resource consumption

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
In short

Tongda OA 2017 has a flaw in a file that processes package resources, allowing attackers to consume excessive server resources remotely. This can slow down or crash the application, affecting availability for legitimate users.

Technical detail

CWE-400 resource exhaustion vulnerability in /inc/package_static_resources.php allows unauthenticated remote attackers to trigger uncontrolled resource consumption through malicious requests, impacting system availability. The vulnerability affects Tongda OA 2017 up to version 11.7.

Summary generated and translated by AI from the official description.
A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the file /inc/package_static_resources.php. The manipulation leads to resource consumption. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
Tongda · OA 2017