An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Hashed passwords are returned to the user when visiting a certain URL.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://zammad.com/news/security-advisory-zaa-2020-04 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2020-03-05T00:37:04
Updated: 2024-08-04T10:50:57.802Z
Reserved: 2020-03-05T00:00:00
Link: CVE-2020-10104

No data.

Status : Modified
Published: 2020-03-05T01:15:12.117
Modified: 2024-11-21T04:54:49.303
Link: CVE-2020-10104

No data.