ZeroHour

CVE-2020-1772

CVSS 3.1
7.5 high
EPSS
2%p75
Published
()
Modified
Description

It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

Vendors
otrsopensusedebian
Products
otrs, backports sle, leap, debian linux
Weakness
CWE-155
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.