First published: Wed Feb 19 2025(Updated: )
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Event Booking Calendar |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51293 is considered a moderate severity vulnerability due to the potential for Denial of Service caused by excessive email sending.
To fix CVE-2023-51293, implement rate limiting for the 'Forgot Password' and 'Email Settings' features in PHPJabbers Event Booking Calendar.
Yes, CVE-2023-51293 can be exploited remotely as it affects user-initiated features without requiring local access.
Exploiting CVE-2023-51293 can lead to a Denial of Service for legitimate users through the generation of a large volume of emails.
As of now, a specific patch for CVE-2023-51293 has not been publicly announced, so users should manually implement rate limiting measures.