In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. NOTE: the Supplier's position is that the pwresettime configuration defaults to 30 minutes, the pwresettime configuration is a hard control enforced via flag PWRESET_STATUS_ALREADYSENT, and no further password-reset email messages are sent if this flag is active for a specific email address.
References
| Link | Resource |
|---|---|
| https://github.com/saykino/CVE-2026-31283 | |
| https://totara.com/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-04-13 15:17
Updated : 2026-06-17 10:33
NVD link : CVE-2026-31283
Mitre link : CVE-2026-31283
CVE.ORG link : CVE-2026-31283
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
