Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gw25-6r8w-p973

Опубликовано: 09 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

CVSS3: 9.8
debian
больше 3 лет назад

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a preve ...

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307