A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.phpjabbers.com/hotel-booking-system/#sectionDemo | product |
https://packetstorm.news/files/id/176486 | vdb entry third party advisory exploit |