An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zammad | Zammad | * | 1.0.3 (including) |
Zammad | Zammad | 1.1.0 (including) | 1.1.0 (including) |
Zammad | Zammad | 1.1.1 (including) | 1.1.1 (including) |
Zammad | Zammad | 1.1.2 (including) | 1.1.2 (including) |
Zammad | Zammad | 1.2.0 (including) | 1.2.0 (including) |