PT-2023-30975 · Unknown · Availability Booking Calendar

Published

2023-12-06

·

Updated

2024-10-09

·

CVE-2023-48831

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Availability Booking Calendar version 5.0
Description A lack of rate limiting in pjActionAJaxSend allows attackers to cause resource exhaustion.
Recommendations For Availability Booking Calendar version 5.0, consider implementing rate limiting in the pjActionAJaxSend function to prevent resource exhaustion. As a temporary workaround, restrict access to the pjActionAJaxSend function until a patch is available.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-48831

Affected Products

Availability Booking Calendar