First published: Wed Feb 19 2025(Updated: )
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Hotel Booking System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51301 is considered a medium severity vulnerability due to its potential to lead to Denial of Service attacks.
To mitigate CVE-2023-51301, implement rate limiting on the 'Login Section, Forgot Email' feature to prevent excessive reset requests.
CVE-2023-51301 can cause disruption through Denial of Service by overwhelming users with excessive email messages.
Yes, CVE-2023-51301 can be exploited remotely by malicious users sending numerous reset requests from different IP addresses.
CVE-2023-51301 affects PHPJabbers Hotel Booking System version 4.0 specifically.