PHPJabbers Hotel Booking System Rate Limiting Vulnerability in Email Settings

Vulnerability

A denial-of-service vulnerability has been identified in PHPJabbers Hotel Booking System version 4.0, stemming from a lack of rate limiting in the 'Email Settings' feature. This vulnerability allows attackers to send a large volume of emails on behalf of a legitimate user, potentially overwhelming the user's inbox.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing a significant increase in email traffic for the affected user.

Reproduction

To reproduce this vulnerability, log into the dashboard and navigate to the 'Email Settings' section under 'System Options'. Enter any email address and name in the respective fields. Capture the request data using Burp Suite and send it to the Intruder tab. Configure the Intruder options and launch the attack. The emails will be received in the inbox of the account used.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.