

Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

Source: CVE-2022-35490

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다