Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfgq-jw59-g278

Опубликовано: 10 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

EPSS

Процентиль: 49%
0.00259
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

CVSS3: 5.3
debian
около 2 лет назад

An issue was discovered in Zammad before 6.2.0. It uses the public end ...

EPSS

Процентиль: 49%
0.00259
Низкий

5.3 Medium

CVSS3