An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://zammad.com/news/security-advisory-zaa-2020-04 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-05T00:37:04
Updated: 2024-08-04T10:50:57.802Z
Reserved: 2020-03-05T00:00:00
Link: CVE-2020-10104
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-05T01:15:12.117
Modified: 2024-11-21T04:54:49.303
Link: CVE-2020-10104
Redhat
No data.