Fiche vulnérabilité
CVE-2023-50455 : faille élevée zammad zammad (CVSS 7.5)
Description
An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 10 déc. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zammad zammad