5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description
CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.
Basic Information
ID
CVE-2025-35432
Source
cisa-cg
Published
Sep 17, 2025 at 16:52
Affected Product
Vendor
CISA
Product
Thorium
Version
1.0.0
Affected Versions
CISA Thorium 1.0.0