CVE-2021-36095 MEDIUM

CVE-2021-36095: User enumeration issue using "lost password" feature

Vendor Otrs Ag
Product ((OTRS)) Community Edition
Weakness CWE-200 · Info exposure
Published September 6, 2021
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

Key dates

02Disclosure timeline

September 6, 2021 CVE published
September 16, 2024 Record updated