A lack of rate limiting in the 'Forgot Password' feature...
Moderate severity
Unreviewed
Published
Feb 20, 2025
to the GitHub Advisory Database
•
Updated Feb 21, 2025
Description
Published by the National Vulnerability Database
Feb 20, 2025
Published to the GitHub Advisory Database
Feb 20, 2025
Last updated
Feb 21, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
References