First published: Mon Aug 28 2023(Updated: )
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpjabbers Hotel Booking System | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40760 is a vulnerability that allows user enumeration in PHP Jabbers Hotel Booking System v4.0.
CVE-2023-40760 can enable an attacker to determine if a user is valid or not during the password recovery process, potentially leading to brute force attacks with valid user accounts.
CVE-2023-40760 is classified as critical with a severity value of 9.8.
To fix CVE-2023-40760, users should update their PHP Jabbers Hotel Booking System to version 4.1 or higher, as this vulnerability has been patched.
For more information about CVE-2023-40760, you can refer to the following sources: [Medium article](https://medium.com/@mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f) and [PHP Jabbers website](https://www.phpjabbers.com/hotel-booking-system/).