forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| genix/cms(Packagist) | 0 | 1.1.2 | N/A |
CVSS Metrics