Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2017-5619
Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
0
Attacker Value
Unknown
CVE-2017-6081
Disclosure Date: March 13, 2017 (last updated November 26, 2024)
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.
0
Attacker Value
Unknown
CVE-2017-5620
Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.
0
Attacker Value
Unknown
CVE-2017-6080
Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie and receive the result.
0
Attacker Value
Unknown
CVE-2017-5621
Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
0