CVE-2025-48738

An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exhaustion for targeted users, reputation damage to the SMTP server, potentially causing it to be blacklisted, and overload of the SMTP server's outbound mail queue.
CVSS

No CVSS.

Configurations

No configuration.

History

28 May 2025, 14:58

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-23 20:15

Updated : 2025-05-28 14:58


NVD link : CVE-2025-48738

Mitre link : CVE-2025-48738

CVE.ORG link : CVE-2025-48738


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling