Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send an excessive number of OTP emails, leading to potential denial-of-service (DoS) conditions or facilitating user harassment through email flooding. Version 1.0.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Schule111
Schule111 schule School Management System |
|
CPEs | cpe:2.3:a:schule111:schule_school_management_system:1.0.0:*:*:*:*:*:*:* | |
Vendors & Products |
Schule111
Schule111 schule School Management System |
|
Metrics |
cvssV3_1
|
Fri, 23 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send an excessive number of OTP emails, leading to potential denial-of-service (DoS) conditions or facilitating user harassment through email flooding. Version 1.0.1 fixes the issue. | |
Title | Schule Missing Rate Limiting on OTP Email Requests – Susceptible to Abuse & DoS | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-23T16:09:49.204Z
Reserved: 2025-05-19T15:46:00.395Z
Link: CVE-2025-48375

Updated: 2025-05-23T16:08:27.582Z

Status : Analyzed
Published: 2025-05-23T16:15:27.113
Modified: 2025-09-05T14:10:02.677
Link: CVE-2025-48375

No data.