An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to the server or the downstream users.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to the server or the downstream users. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-25T00:00:00.000Z
Updated: 2025-11-25T21:37:29.528Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51741
Updated: 2025-11-25T21:37:24.760Z
Status : Awaiting Analysis
Published: 2025-11-25T21:15:55.743
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-51741
No data.