← Back to CVE List

CVE-2020-1772

Published: 2020-03-27T13:15Z
Last Modified: 2024-11-21T05:11Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt