CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may lead to a denial-of-service condition.
CVE
CVE-2022-35488
Severity
HIGH
CVSS
7.5
EPSS
0.75%
Original NVD Description
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
Related CVEs
Other vulnerabilities affecting the same vendor(s)