Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zammad 资源管理错误漏洞
Vulnerability Description
Zammad是德国Zammad公司的一套票务管理软件。 Zammad 5.2.0版本存在安全漏洞,该漏洞源于其“忘记密码”功能未进行请求速率限制导致攻击者可以通过向受害者发送许多请求,生成过多电子邮件导致拒绝服务和造成垃圾邮件。
CVSS Information
N/A
Vulnerability Type
N/A