PT-2023-10282 · Unknown · Internalerror503 Forget It
Published
2023-04-17
·
Updated
2024-05-17
·
CVE-2015-10103
CVSS v2.0
1.7
Low
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
InternalError503 Forget It versions up to 1.3
Description
A problematic issue was found in InternalError503 Forget It, affecting an unknown part of the file js/settings.js. The manipulation of the
setForgetTime argument with the input 0 leads to an infinite loop. It is possible to launch the attack on the local host. Upgrading to version 1.4 is able to address this issue.Recommendations
For versions up to 1.3, upgrade to version 1.4 to address the issue. As a temporary workaround, consider restricting the use of the
setForgetTime argument to prevent infinite loop exploitation.Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internalerror503 Forget It