Improper control of interaction frequency in Wekan - #VU147309
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control of interaction frequency in the forgotPassword DDP method in server/models/users.js when processing repeated password-reset requests. A remote attacker can submit repeated forgotPassword requests to cause a denial of service.
SMTP must be configured for exploitation.