CVE-2017-5619

An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
References
Link Resource
http://www.securityfocus.com/bid/96937 Third Party Advisory VDB Entry
https://zammad.com/de/news/security-advisory-zaa-2017-01 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:zammad:zammad:1.2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-03-13 06:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-5619

Mitre link : CVE-2017-5619

CVE.ORG link : CVE-2017-5619


JSON object : View

Products Affected

zammad

  • zammad
CWE
CWE-287

Improper Authentication