Описание
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (включая)
Одно из
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00443
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
debian
почти 9 лет назад
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, an ...
CVSS3: 9.8
github
больше 3 лет назад
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
EPSS
Процентиль: 63%
0.00443
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-287