← Voltar para CVEs
CVE-2026-31283
N/ADescricao
In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado4/13/2026
Ultima modificacao4/13/2026
Fontenvd
Avistamentos honeypot0
Referencias
https://github.com/saykino/CVE-2026-31283(cve@mitre.org)
https://totara.com/(cve@mitre.org)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.