PT-2025-7305 · Phpjabbers · Phpjabbers Shared Asset Booking System

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2023-51323

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPJabbers Shared Asset Booking System version 1.0
Description A lack of rate limiting in the 'Forgot Password' feature allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Recommendations For PHPJabbers Shared Asset Booking System version 1.0, consider implementing rate limiting in the 'Forgot Password' feature to prevent excessive email sending. As a temporary workaround, consider disabling the 'Forgot Password' feature until a patch is available. Restrict access to the 'Forgot Password' feature to minimize the risk of exploitation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51323

Affected Products

Phpjabbers Shared Asset Booking System