Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2jx-4h7c-9mg2

Опубликовано: 09 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

EPSS

Процентиль: 59%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

CVSS3: 7.5
debian
больше 3 лет назад

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the ...

EPSS

Процентиль: 59%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-400