Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46rp-6wrc-96x2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file 404.html (/zammad/public/404.html)

An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file 404.html (/zammad/public/404.html)

EPSS

Процентиль: 58%
0.00363
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks. Source code was disclosed for the file 404.html (/zammad/public/404.html)

CVSS3: 5.3
debian
почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It returns source c ...

EPSS

Процентиль: 58%
0.00363
Низкий

Дефекты

CWE-200