Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send an excessive number of OTP emails, leading to potential denial-of-service (DoS) conditions or facilitating user harassment through email flooding. Version 1.0.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 23 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send an excessive number of OTP emails, leading to potential denial-of-service (DoS) conditions or facilitating user harassment through email flooding. Version 1.0.1 fixes the issue. | |
Title | Schule Missing Rate Limiting on OTP Email Requests – Susceptible to Abuse & DoS | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-23T15:41:11.735Z
Updated: 2025-05-23T16:09:49.204Z
Reserved: 2025-05-19T15:46:00.395Z
Link: CVE-2025-48375

Updated: 2025-05-23T16:08:27.582Z

Status : Awaiting Analysis
Published: 2025-05-23T16:15:27.113
Modified: 2025-05-28T14:58:52.920
Link: CVE-2025-48375

No data.