Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50453
HistoryDec 10, 2023 - 7:15 p.m.

Design/Logic Flaw

2023-12-1019:15:00
PRIOn knowledge base
www.prio-n.com
2
zammad
design flaw
logic flaw
public endpoint
user object
internal configuration data

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Related for PRION:CVE-2023-50453