Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpff-gfqx-47wg

Опубликовано: 28 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

EPSS

Процентиль: 62%
0.00434
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 9.1
nvd
почти 4 года назад

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

CVSS3: 9.1
debian
почти 4 года назад

An access control issue in Zammad v5.0.3 allows attackers to write ent ...

EPSS

Процентиль: 62%
0.00434
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-668