Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97697
HistoryDec 13, 2023 - 12:00 a.m.

Zammad Information Disclosure Vulnerability (CNVD-2023-9769727)

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
zammad
ticket management
information disclosure
vulnerability
public endpoint
user object attributes
sensitive information
exploit

6.2 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Zammad is a suite of ticket management software from the German company Zammad. Zammad suffers from an information disclosure vulnerability that stems from the use of the public endpoint /api/v1/signshow as its login screen, which returns internal configuration data for user object attributes. An attacker could exploit this vulnerability to obtain sensitive information.

CPENameOperatorVersion
zammad zammadeq6.1.0

6.2 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Related for CNVD-2023-97697