PT-2023-10282 · Unknown · Internalerror503 Forget It

Published

2023-04-17

·

Updated

2024-05-17

·

CVE-2015-10103

CVSS v2.0

1.7

Low

VectorAV:L/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions InternalError503 Forget It versions up to 1.3
Description A problematic issue was found in InternalError503 Forget It, affecting an unknown part of the file js/settings.js. The manipulation of the setForgetTime argument with the input 0 leads to an infinite loop. It is possible to launch the attack on the local host. Upgrading to version 1.4 is able to address this issue.
Recommendations For versions up to 1.3, upgrade to version 1.4 to address the issue. As a temporary workaround, consider restricting the use of the setForgetTime argument to prevent infinite loop exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2015-10103

Affected Products

Internalerror503 Forget It