Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35490

Опубликовано: 08 авг. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zammad:zammad:5.2.0:-:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:5.2.0:alpha:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
debian
больше 3 лет назад

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a preve ...

CVSS3: 9.8
github
больше 3 лет назад

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307