CVE-2020-1772

CVE-2020-1772

It’s possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

Source: CVE-2020-1772

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다