Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zammad 安全漏洞
Vulnerability Description
Zammad是德国Zammad公司的一套票务管理软件。 Zammad 6.3.0 之前版本存在安全漏洞,该漏洞源于Zammad Upload Cache使用不安全、部分可猜测的 FormID 来识别内容,攻击者利用该漏洞可能会将恶意内容上传到他们无法访问的文章草稿中。
CVSS Information
N/A
Vulnerability Type
N/A