CVE-2017-5619

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
References
Link Resource
https://zammad.com/de/news/security-advisory-zaa-2017-01 Vendor Advisory
http://www.securityfocus.com/bid/96937 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zammad:zammad:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.0:*:*:*:*:*:*:*

Information

Published : 2017-03-12 23:59

Updated : 2019-10-02 17:03


NVD link : CVE-2017-5619

Mitre link : CVE-2017-5619


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

zammad

  • zammad