PT-2025-7312 · Phpjabbers · Phpjabbers Meeting Room Booking System

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2023-51332

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPJabbers Meeting Room Booking System version 1.0
Description A lack of rate limiting in the 'Forgot Password' feature allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Recommendations For PHPJabbers Meeting Room Booking System version 1.0, consider implementing rate limiting in the 'Forgot Password' feature to prevent excessive email sending. As a temporary workaround, consider disabling the 'Forgot Password' feature until a patch is available. Restrict access to the 'Forgot Password' feature to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51332

Affected Products

Phpjabbers Meeting Room Booking System