First published: Mon Mar 13 2017(Updated: )
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | <=1.0.3 | |
Zammad Zammad | =1.1.0 | |
Zammad Zammad | =1.1.1 | |
Zammad Zammad | =1.1.2 | |
Zammad Zammad | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.