Junglewise Threat Intelligence

CVE-2025-51741: Veal98 Echo uncontrolled resource consumption in password reset endpoint

CVE-2025-51741 · Severity: high · CVSS 7.5 · Published 2025-11-25

Executive brief

A vulnerability in the Echo Open-Source Community System allows unauthorized individuals to trigger mass email dispatches. By repeatedly calling the password reset function, an attacker can flood the server's email queue or harass users with unwanted messages. This can lead to a denial of service for the email system and potentially damage the organization's reputation or result in the server being blacklisted by email providers.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the /sendEmailCodeForResetPwd endpoint of the Echo Open-Source Community System. Unauthenticated remote attackers can exploit this by sending crafted POST requests where the 'kaptcha' parameter matches the 'kaptchaOwner' cookie value. By supplying arbitrary usernames and automating the requests, an attacker can bypass intended rate limits or verification steps to trigger repeated email dispatches. This results in a denial of service (DoS) affecting the server's mail resources or the downstream users (email bombing). As of the advisory date, no official patch has been confirmed in the provided references.

Affected products

  • Veal98 (jcool98) Echo Open-Source Community System 2.2 - 2.3

Timeline

  • 2025-11-23: disclosed: Vulnerability discovered and documented by Paxsizy.
  • 2025-11-25: advisory: CVE-2025-51741 published.

References