7.5
CVSSv3

CVE-2020-1772

Published: 27/03/2020 Updated: 31/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

It's possible to craft Lost Password requests with wildcards in the Token value, which allows malicious user to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs

opensuse leap 15.1

opensuse backports sle 15.0

opensuse leap 15.2

debian debian linux 8.0