# CVE-2025-54320 Invite User Email Bombing
Description
The invitation API does not implement rate limiting for the target email address. This allows for an Email Bombing attack.
------------------------------------------
CVSS Score: 7.1 (High)
------------------------------------------
Attack Type
* Remote (Authenticated)
------------------------------------------
Affected Versions
* Versions before <= 8.6.8
------------------------------------------
Vendor of Product
* Ascertia
------------------------------------------
Affected Product Code Base
* SigningHub
------------------------------------------
Affected Component
* Invite User API.
------------------------------------------
Mitigations
* Implement rate-limit for the Invite User API.
------------------------------------------
Vulnerability Details
* an attacker can floods a target's inbox with a large volume of invite emails in a short period of time.
------------------------------------------
Fixed versions
* Versions after > 8.6.8
------------------------------------------
Discovered By:
* Yazan Abu-Nadi
[4.0K] /data/pocs/b1e12560d34c6b60dc56a01f3873e092d56e6fd9
└── [1.1K] README.md
1 directory, 1 file