ZeroHour

CVE-2020-12645

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

Vendors
open-xchange
Products
open-xchange appsuite
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.