PT-2025-7304 · Phpjabbers · Phpjabbers Night Club Booking

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2023-51321

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPJabbers Night Club Booking Software version 1.0
Description A lack of rate limiting in the 'Forgot Password' feature allows attackers to send an excessive amount of email to a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. The Forgot Password feature is vulnerable due to the lack of rate limiting, allowing attackers to exploit this weakness.
Recommendations For PHPJabbers Night Club Booking Software version 1.0, consider implementing rate limiting in the Forgot Password feature to prevent excessive email sending. As a temporary workaround, consider disabling the Forgot Password feature until a patch is available. Restrict access to the Forgot Password functionality to minimize the risk of exploitation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51321

Affected Products

Phpjabbers Night Club Booking