← Zurück zur CVE-Suche

CVE-2026-31283

Totara LMS

Beschreibung

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack.

CVSS 9.8EPSS 0.39699999999999996%Risiko 1.02
Quelle öffnen
Veröffentlicht
2026-04-13 15:17:33
Betroffene Versionen
<=v19.1.5
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H