Description
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
No analysis available yet.
Remediation
Vendor Solution
Update to OTRS 7.0.29.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22727 | Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions. |
References
History
Mon, 16 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | User enumeration issue using "lost password" feature | User enumeration issue using "lost password" feature |
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-16T17:58:45.926Z
Reserved: 2021-07-01T00:00:00.000Z
Link: CVE-2021-36095
No data.
Status : Modified
Published: 2021-09-06T14:15:07.313
Modified: 2024-11-21T06:13:08.900
Link: CVE-2021-36095
No data.
OpenCVE Enrichment
No data.
EUVD