Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mxr8-qj6j-f7gq

Опубликовано: 26 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

EPSS

Процентиль: 56%
0.00332
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

CVSS3: 9.1
debian
почти 2 года назад

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cach ...

EPSS

Процентиль: 56%
0.00332
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-639