An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.
{
"versions": [
{
"introduced": "6.2.0"
},
{
"fixed": "6.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-alpha"
}
]
}