PT-2025-7299 · Phpjabbers · Phpjabbers Bus Reservation System

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2023-51316

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PHPJabbers Bus Reservation System version 1.1
Description A lack of rate limiting in the 'Forgot Password' feature allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Recommendations For PHPJabbers Bus Reservation System version 1.1, consider implementing rate limiting in the 'Forgot Password' feature to prevent excessive email generation. As a temporary workaround, consider disabling the 'Forgot Password' feature until a patch is available. Restrict access to the 'Forgot Password' functionality to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51316

Affected Products

Phpjabbers Bus Reservation System