Resource Exhaustion Vulnerability in Appointment Scheduler by PHPJabbers
CVE-2023-48840
7.5HIGH
Summary
The Appointment Scheduler 3.0 from PHPJabbers exhibits a serious vulnerability due to a lack of effective rate limiting in the pjActionAjaxSend function. This flaw allows attackers to exploit the system, potentially leading to resource exhaustion, which can degrade performance or lead to service denial. With this vulnerability, attackers can purposely overload the server by sending multiple requests, ultimately disrupting the availability of the Appointment Scheduler service.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved