An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
References
Link Resource
http://www.securityfocus.com/bid/96937 Third Party Advisory VDB Entry
https://zammad.com/de/news/security-advisory-zaa-2017-01 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-03-13T06:14:00

Updated: 2017-03-17T09:57:01

Reserved: 2017-01-29T00:00:00


Link: CVE-2017-5619

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-03-13T06:59:00.293

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-5619

JSON object: View

cve-icon Redhat Information

No data.

CWE