PT-2026-81147 · Rocket.Chat · Rocket.Chat
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rocket.Chat (affected versions not specified)
Description
An unauthenticated caller can repeatedly invoke the
sendForgotPasswordEmail Meteor method because it lacks a DDP rate limit. This method is accessible via DDP and the HTTP endpoint 'POST /api/v1/method.callAnon/sendForgotPasswordEmail'. Exploitation allows an attacker to send an unlimited volume of password reset emails to a specific address using the system's mail sender. Additionally, the method can be used to probe for accounts; it returns true for addresses without an account or for successful sends, but returns false for accounts using external providers when Accounts AllowPasswordChangeForOAuthUsers is disabled, allowing an attacker to identify those specific account types.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rocket.Chat