|
208161
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The …
|
NVD-CWE-noinfo
|
CVE-2020-26034
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208162
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
|
CWE-352
Origin Validation Error
|
CVE-2020-26033
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208163
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can u…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26032
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208164
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26031
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208165
|
9.8 |
CRITICAL
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticate…
|
CWE-287
Improper Authentication
|
CVE-2020-26030
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208166
|
6.5 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not …
|
CWE-863
Incorrect Authorization
|
CVE-2020-26029
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208167
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
|
CWE-863
Incorrect Authorization
|
CVE-2020-26028
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208168
|
10.0 |
CRITICAL
Network
|
browserup
|
browserup_proxy
|
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it …
|
-
|
CVE-2020-26282
|
2024-11-21 14:19 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208169
|
8.5 |
HIGH
Network
|
gohugo
|
hugo
|
Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%…
|
CWE-78
OS Command
|
CVE-2020-26284
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208170
|
7.5 |
HIGH
Network
|
rust-lang
|
async-h1
|
async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async…
|
-
|
CVE-2020-26281
|
2024-11-21 14:19 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|