Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2017-5619

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
0
Attacker Value
Unknown

CVE-2017-6081

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.
0
Attacker Value
Unknown

CVE-2017-5620

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.
0
Attacker Value
Unknown

CVE-2017-6080

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie and receive the result.
0
Attacker Value
Unknown

CVE-2017-5621

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via malicious HTML in a chat message or the content of a ticket article, when using either the REST API or the WebSocket API.
0