CVE-2017-5619: Critical severity Zammad Zammad vulnerability
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5619?
CVE-2017-5619 has a high severity rating due to the potential for attackers to gain unauthorized access to accounts.
How do I fix CVE-2017-5619?
To fix CVE-2017-5619, upgrade Zammad to version 1.0.4, 1.1.3, or 1.2.1 or later.
What does CVE-2017-5619 exploit?
CVE-2017-5619 exploits a vulnerability that allows attackers to log in using hashed passwords instead of the actual password.
Which versions of Zammad are affected by CVE-2017-5619?
CVE-2017-5619 affects Zammad versions prior to 1.0.4, 1.1.x versions before 1.1.3, and 1.2.x versions before 1.2.1.
What should I do if I am using a vulnerable version of Zammad related to CVE-2017-5619?
If you are using a vulnerable version of Zammad, implement the necessary updates immediately to mitigate this security risk.