Menu

Post image 1
Post image 2
1 / 2
0

GHSA-RGJ7-VG8V-J4WR: GHSA-RGJ7-VG8V-J4WR: Unauthenticated Engagement Metric Inflation in Ech0

DEV Community·CVE Reports·25 days ago
#jj8szkrn
Reading 0:00
15s threshold

GHSA-RGJ7-VG8V-J4WR: Unauthenticated Engagement Metric Inflation in Ech0 Vulnerability ID: GHSA-RGJ7-VG8V-J4WR CVSS Score: 5.3 Published: 2026-05-07 The Ech0 lightweight publishing platform suffers from a missing authentication check (CWE-306) and missing authorization (CWE-862) on the PUT /api/echo/like/:id API endpoint. This vulnerability allows an unauthenticated remote attacker to arbitrarily inflate engagement metrics by repeatedly sending requests, falsifying social proof and generating unnecessary database writes. TL;DR A critical API endpoint in the Ech0 publishing platform was exposed publicly without authentication or user-binding checks. Remote attackers can leverage this to artificially inflate the "like" count of any post via repeated HTTP requests.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More