What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.
Explanation of Vulnerability in Simple Terms
02Summary
Appointment Hour Booking versions up to 1.4.56 contain a weakness in rate limiting or brute-force protection that allows attackers to perform repeated actions without adequate throttling. An attacker can make many requests in quick succession over the network without authentication. This could enable password guessing, token enumeration, or other abuse of the booking system.
What an attacker can do
03Attacker Capabilities
Make repeated requests to the booking system without being throttled or blocked.
Potential impact on your site
04Site Impact
Attackers can brute-force passwords, enumerate valid booking slots or user accounts, or disrupt service availability through request flooding.
Conditions required to exploit
05Prerequisites
Network access to the vulnerable site; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 17, 2024
CVE published
April 28, 2026
Record updated