HIGH
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim
Published Aug 8, 2022
7.5
HIGHCVSS 3.1
EPSS 0.85%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.