Vulnerability Details CVE-2023-50453
An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.3%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2023-50453
-
cpe:2.3:a:zammad:zammad:6.1.0
-
cpe:2.3:a:zammad:zammad:6.2.0