PHPJabbers Bus Reservation System
cpe:2.3:a:phpjabbers:bus_reservation_system:*:*:*:*:*:*:*
- 1.1
A denial-of-service vulnerability has been identified in PHPJabbers Bus Reservation System version 1.1, stemming from a lack of rate limiting in the 'Forgot Password' feature. This oversight allows attackers to flood a legitimate user's email with password reset requests, potentially overwhelming the user's inbox.
Exploitation of this vulnerability can lead to a denial-of-service condition for the affected user, caused by an excessive number of generated email messages.
To reproduce this vulnerability, log into the PHPJabbers Bus Reservation System demo as an admin. Use Burp Suite to capture the 'Forgot Password' request and send it to the Intruder tab. Configure the Intruder to send a large number of requests to the 'Forgot Password' feature for a single user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.