ZeroHour

CVE-2022-32741

CVSS 3.1
5.3 medium
EPSS
<1%p56
Published
()
Modified
Description

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

Vendors
otrs
Products
otrs
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.