CVE-2022-35488
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
HIGH · CVSS 7.5
EPSS 0.00389
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0