PHPJabbers Meeting Room Booking System Rate Limiting Vulnerability in Forgot Password Feature

Vulnerability

A denial-of-service vulnerability has been identified in PHPJabbers Meeting Room Booking System version 1.0, stemming from a lack of rate limiting in the 'Forgot Password' feature. This oversight allows attackers to inundate a legitimate user's email with password reset requests, potentially overwhelming the user's inbox.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition for the affected user, caused by an excessive volume of generated email messages.

Reproduction

To reproduce this vulnerability, log into the PHPJabbers Meeting Room Booking System demo as an admin. Navigate to the 'Forgot Password' feature and use Burp Suite to capture the request. Send the request to the Intruder tab, configure the attack, and start it. The result will be a flood of password reset emails sent to the registered email account.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.