Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26034

Опубликовано: 28 дек. 2020
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 3.4.1 (исключая)

EPSS

Процентиль: 45%
0.00226
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
debian
около 5 лет назад

An account-enumeration issue was discovered in Zammad before 3.4.1. Th ...

github
больше 3 лет назад

An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.

EPSS

Процентиль: 45%
0.00226
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo