CVE-2023-2666: Allocation of Resources Without Limits or Throttling in froxlor/froxlor
Published May 12, 2023
·Updated
Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.
Other sources
Froxlor prior to 2.0.16 has a password reset page with no rate limit.
Affected Software
2 affected componentsFixes available
composer/froxlor/froxlor<2.0.16
2.0.16
Froxlor Froxlor<2.0.16
Remediation
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
May 19, 2023
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-2666?
The severity of CVE-2023-2666 is high.
2
What is the affected software version for CVE-2023-2666?
The affected software version for CVE-2023-2666 is froxlor prior to 2.0.16.
3
How can I fix CVE-2023-2666?
To fix CVE-2023-2666, update your froxlor installation to version 2.0.16 or newer.
4
What is the CWE ID for CVE-2023-2666?
The CWE ID for CVE-2023-2666 is 770.
5
Where can I find more information about CVE-2023-2666?
You can find more information about CVE-2023-2666 at the following references: https://github.com/froxlor/froxlor/commit/1679675aa1c29d24344dd2e091ff252accb111d6 and https://huntr.dev/bounties/0bbdc9d4-d9dc-4490-93ef-0a83b451a20f.