Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-1773 – An attacker with the ability to generate session IDs or password reset to

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1773

Reference (s):

  • https://otrs.com/release-notes/otrs-security-advisory-2020-10/
  • SUSE:openSUSE-SU-2020:0551
  • URL: http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html
  • SUSE:openSUSE-SU-2020:1475
  • URL: http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser