Vulnerabilities > Zammad > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-10 CVE-2023-50455 Allocation of Resources Without Limits or Throttling vulnerability in Zammad 6.1.0/6.2.0
An issue was discovered in Zammad before 6.2.0.
network
low complexity
zammad CWE-770
7.5
2022-08-08 CVE-2022-35487 Incorrect Authorization vulnerability in Zammad 5.2.0
Zammad 5.2.0 suffers from Incorrect Access Control.
network
low complexity
zammad CWE-863
7.5
2022-08-08 CVE-2022-35488 Unspecified vulnerability in Zammad 5.2.0
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
network
low complexity
zammad
7.5
2022-04-27 CVE-2022-29700 Weak Password Requirements vulnerability in Zammad 5.1.0
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
network
low complexity
zammad CWE-521
7.5
2022-04-27 CVE-2022-29701 Allocation of Resources Without Limits or Throttling vulnerability in Zammad 5.1.0
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
network
low complexity
zammad CWE-770
7.5
2022-02-04 CVE-2021-43145 Unspecified vulnerability in Zammad 5.0.1
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
network
low complexity
zammad
8.1
2021-10-07 CVE-2021-42086 Unspecified vulnerability in Zammad
An issue was discovered in Zammad before 4.1.1.
network
low complexity
zammad
8.8
2021-10-07 CVE-2021-42089 Information Exposure vulnerability in Zammad
An issue was discovered in Zammad before 4.1.1.
network
low complexity
zammad CWE-200
7.5
2021-10-07 CVE-2021-42093 Unspecified vulnerability in Zammad
An issue was discovered in Zammad before 4.1.1.
network
low complexity
zammad
7.2
2021-06-28 CVE-2021-35299 Information Exposure Through Log Files vulnerability in Zammad
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
network
low complexity
zammad CWE-532
7.5