Impact
The flaw allows a malicious actor to lock out a patient across all tenants that share the same email hash on an OpenReception instance. By repeatedly sending failed PIN challenge responses against one tenant, the attacker causes the shared throttle row to trigger a lockout that applies to the same email address on every tenant. Each failed attempt escalates the lockout duration, leading to sustained denial of service when the victim attempts to schedule appointments on any tenant.
Affected Systems
OpenReception appointment‑booking software, versions prior to 1.0.4, uses a central challenge_throttle table shared by all tenants. The fix was applied in version 1.0.4.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity that mainly affects availability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers only need to know the target’s email and have access to an API endpoint on at least one tenant. The attack path is remote and does not require privileged credentials.
OpenCVE Enrichment