Security Advisory

CVE-2022-29701

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-27 02:47:11
Last updated 2024-08-03 06:33:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.