CVE-2020-26034: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether the input supplied was recognized as associated with a valid user.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26034?
CVE-2020-26034 is an account-enumeration issue discovered in Zammad before 3.4.1.
2
What is the severity of CVE-2020-26034?
The severity of CVE-2020-26034 is medium with a CVSS score of 4.3.
3
How does CVE-2020-26034 affect Zammad?
CVE-2020-26034 affects Zammad versions before 3.4.1.
4
How can an anonymous user exploit CVE-2020-26034?
An anonymous user can exploit CVE-2020-26034 by guessing valid user email addresses and observing the application's response.
5
Is there a fix for CVE-2020-26034?
Yes, the fix for CVE-2020-26034 is available in Zammad version 3.4.1.