CVE-2017-5619

EUVD-2017-14716
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
zammadzammad
𝑥
≤ 1.0.3
zammadzammad
1.1.0
zammadzammad
1.1.1
zammadzammad
1.1.2
zammadzammad
1.2.0
𝑥
= Vulnerable software versions